Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill declares executable shell-related capabilities through required binaries and operational notes, but does not expose an explicit permissions model to constrain or communicate those actions. In an agent setting, this can lead to unexpected command execution against local files or network targets, especially since the notes explicitly mention user-provided file paths and endpoints.
