Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to invoke a local shell wrapper (`scripts/exa-with-key.sh`) and describes credential discovery from environment variables and local files, but it declares no corresponding permissions or trust boundaries. This creates a real capability/permission mismatch: an agent may execute shell commands and access sensitive local credentials or arbitrary endpoints via the `raw` mode without users or policy systems being explicitly informed.
