Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill invokes a shell script (`scripts/rename-topic.sh`) and requires a Telegram bot token, but the manifest does not declare permissions or clearly bound what external actions it can perform. That mismatch can cause the agent or user to authorize a skill without understanding that it can execute shell commands and make live changes to Telegram topics, increasing the risk of unintended or overbroad execution.
