Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs users to run local shell scripts (for example, `bash scripts/*.sh`) but does not declare corresponding permissions or clearly surface that executable shell capability is required. This creates a transparency and trust problem: users may invoke shell-based actions that handle tokens, upload files, and contact external APIs without having been warned through the skill's permission model.
