Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly instructs use of shell commands (`ganglion`, `curl`, `jq`) and remote HTTP operations, but the frontmatter does not declare any permissions or guardrails for shell/network use. This mismatch can cause an agent platform to invoke powerful command execution capabilities without explicit user-visible consent boundaries, increasing the chance of unintended local execution or remote side effects.
