Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to run shell commands and Python scripts, install packages, and use curl against external APIs, yet no permissions are declared. That creates a capability/consent mismatch: an orchestrator or reviewer may treat the skill as low-risk while it can actually execute code and make networked requests.
