Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill is explicitly user-invocable and documents shell-script execution, but no permissions are declared to signal that capability. This weakens transparency and policy enforcement because users or orchestrators may not realize the skill executes local shell commands, network calls, and file writes.
