Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises shell-based execution via curl and script invocation, but the file does not declare permissions corresponding to that capability. This creates a trust and review gap: an agent or platform may treat the skill as lower risk than it actually is, while the skill can still trigger networked shell actions using API credentials.
