Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill exposes shell execution behavior and use of sensitive environment variables, but it does not declare permissions in a security-facing way that would let users or a platform evaluate those capabilities up front. Because it launches local commands, uses tmux, and relies on API keys for external services, the undeclared capability surface increases the chance of unexpected command execution and data handling without informed consent.
