Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation instructs users to run shell commands such as pip install and python3 invocation, which indicates shell execution capability, but the skill metadata declares no permissions. This mismatch is a real security issue because permissionless appearance can mislead users or orchestrators about what the skill can do, reducing transparency and weakening permission-based controls.
