Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill instructs the agent to execute shell commands that modify installed hashed dist JavaScript files, create backups, restart the gateway, and run curl-based verification, but no explicit permissions are declared. This creates a real security concern because a caller may invoke powerful local code-execution and service-modification behavior without clear sandboxing or operator approval boundaries, increasing the risk of unauthorized file tampering or operational disruption.
