Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill directs the assistant to run shell commands (`mkdir`, `printf`, `chmod`, `curl`, `jq`) but does not declare permissions or otherwise constrain that capability. Hidden shell use increases the chance of unexpected local side effects and makes it easier for a user-provided secret to be handled outside an explicit permission boundary.
