Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill advertises operational shell capability via curl and a submission script, but the manifest does not declare permissions for that capability. This creates a transparency and policy gap: an agent or reviewer may underestimate what the skill can do, including making outbound requests with sensitive prompt data or secrets.
