Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises shell-driven behavior (`bash scripts/*.sh`, `curl`) without declaring corresponding permissions, which weakens the trust boundary and can cause operators or runtimes to authorize execution they did not explicitly consent to. In this file, the undeclared shell capability is especially concerning because the shell commands initiate registration, persistent file writes, and recurring network activity.
