Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documents direct shell execution of multiple scripts (`bash scripts/*.sh ...`) but does not declare corresponding permissions or execution scope. This creates a trust and review gap: an agent or user may approve the skill based on metadata that understates its real capabilities, increasing the chance of unintended command execution or unsafe handling of parameters and environment data.
