Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises shell-based setup and operational commands in SKILL.md, but the metadata only declares required binaries and environment variables, not explicit permissions for shell execution. In an agent ecosystem, undeclared execution capability weakens trust boundaries and can cause users or orchestrators to run local scripts with filesystem access they did not clearly authorize.
