Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises and relies on shell/Python execution but does not declare permissions or constraints for that capability. In an agent environment, undeclared command execution expands the attack surface and can let a loosely triggered skill inspect local files, invoke CLIs, and act on authenticated home-automation state without clear user awareness or platform enforcement.
