Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documentation instructs users to run shell commands and script files, but the skill declares no permissions for shell/code execution. This mismatch can mislead users and downstream tooling about the skill's actual capabilities, weakening trust boundaries and permission review even though the shown commands are ordinary installation and usage steps.
