Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises shell-based usage (`./scripts/context.sh`, `curl`) but does not declare corresponding permissions or clearly scope its runtime capabilities. This can mislead users and host systems about what the skill may execute, weakening permission-based trust and review controls even if the shell actions are only for installation or API access.
