Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs the agent to execute a local shell script (`arcadia.sh`) and declares runtime dependencies (`curl`, `jq`), which are shell execution capabilities, yet no corresponding permissions are declared. Undeclared shell capability weakens sandboxing and trust boundaries because a host may allow the skill to run with broader execution power than users expect.
