Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises executable shell commands, environment-variable inputs, and file writes, but declares no permissions or trust boundaries. That creates a real security issue because an agent or user may invoke network operations and write persistent data without explicit approval, increasing the chance of unintended command execution, data persistence, or policy bypass.
