Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill advertises shell-based commands in its documentation but does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap: an agent or runtime may infer command execution is acceptable without a clear least-privilege boundary, increasing the chance of unintended shell access or misuse if the skill is invoked in a permissive environment.
