Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill advertises shell execution, network access, and local file writes, but these capabilities are not declared through a formal permission mechanism; they are only described in markdown metadata/instructions. That creates a policy-enforcement gap: an agent or platform may execute commands with broader trust than intended, and user-controlled parameters such as route/stop names increase risk if the runtime interpolates them into shell commands unsafely.
