Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill contains repeated shell command instructions (`curl`) but does not declare corresponding permissions. That creates a capability/permission mismatch that can bypass user expectations and policy controls, especially since the skill is designed to contact external services on a schedule. In this context, undeclared shell/network behavior is materially risky rather than a harmless documentation issue.
