Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to invoke shell commands and local Python scripts, but it does not declare any explicit tool scope such as allowed-tools or permissions. That creates an overbroad execution surface: if this skill is selected in an environment with shell access, it can run commands against attacker-supplied document paths and external utilities without a clear policy boundary, increasing the risk of unintended command execution or unsafe file handling.
