Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill executes shell commands (`curl`, `jq`, file reads/writes, `rm`) but does not declare corresponding permissions, which weakens the platform's ability to gate risky capabilities and inform users. In this context the shell is used to access local credential files and transmit health data to a remote service, so undeclared capability use materially increases security and transparency risk.
