Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to execute shell commands such as `which murmur`, `brew install`, `git clone`, `bun install`, `murmur beat`, and `murmur init`, but the skill metadata does not declare permissions or warn clearly about command execution. This creates a capability/permission mismatch that can lead to unexpected local system changes and makes review and policy enforcement harder.
