Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill declares shell capability requirements via `curl` in metadata and execution guidance, but the static finding indicates those capabilities are not reflected in an explicit permissions declaration. That mismatch can weaken review and policy enforcement because users or platforms may not realize the skill can initiate networked shell actions that handle secrets like `POYO_API_KEY`.
