Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill directs the agent to execute shell commands (`source`, `ffprobe`, `lasutil`, background scripts) but does not declare shell permissions. Hidden execution capability undermines least-privilege review and can lead to unintended command execution or broader access than users expect. The workflow context makes this more concerning because it processes local files and credentials, so shell access materially expands risk.
