Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises and instructs use of shell commands (`curl`, `bash`) but the manifest shown in this file does not declare corresponding permissions or execution expectations. That mismatch can cause agents or operators to run networked shell actions without informed consent or policy gating, increasing the chance of unauthorized external calls and unsafe setup behavior.
