Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill declares no permissions, yet the analyzed behavior indicates shell-capable actions. That is dangerous because users and the host platform cannot accurately assess or constrain what the skill may do, increasing the chance of unexpected command execution or environmental changes during install or runtime.
