Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to execute a local shell script (`bash search.sh`) that performs live network requests via `curl`, yet the skill declares no corresponding permissions or trust boundaries. This creates an undeclared capability gap: users and the hosting platform may believe the skill is metadata-only while it can actually invoke shell and network access, increasing the risk of unexpected command execution, data exfiltration, or abuse of the runtime environment.
