Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill invokes shell commands (`curl`, shell pre-flight check, and helper script usage) but does not declare permissions/capabilities accordingly. This creates a transparency and policy gap: users or platforms may not realize the skill can execute shell operations and make outbound requests, increasing the risk of unsafe execution or improper sandboxing.
