Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises shell-based installation and CLI commands but does not declare corresponding permissions, creating a transparency and consent gap. In agent runtimes, undeclared execution capability can lead to unexpected command execution, repository cloning, symlink creation, or other filesystem-affecting actions without clear user awareness.
