Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill relies on shell execution but does not declare corresponding permissions, which weakens transparency and any permission-based safety controls around command execution. In this context, shell access is especially sensitive because the documentation also directs the agent to run an installer script and a CLI that can authenticate to Google accounts and access user data.
