Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill clearly instructs the agent to execute local shell scripts, but it does not declare corresponding permissions or execution boundaries. This creates a capability mismatch that can lead to unexpected command execution in environments that rely on permission metadata for policy enforcement or user consent.
