Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 78% confidence
- Finding
- The skill invokes Node.js scripts and explicitly supports passing an external shell evaluation command via `--eval_cmd`, which implies access to environment-dependent execution despite declaring no permissions. This mismatch is dangerous because operators may assume the skill is low-privilege, while in practice it can run commands that inherit secrets and environment variables from the host process.
