Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises shell scripts and multiple external data sources, which implies network and shell execution capabilities, yet no permissions are declared in the manifest. This creates a transparency and governance gap: users or hosting platforms cannot accurately assess what the skill is allowed to do, and any later script changes could expand outbound access or command behavior without an explicit permission boundary.
