Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill advertises shell-based execution via curl in metadata and instructions but does not declare corresponding permissions. That creates a capability/permission mismatch, which can bypass user expectations and security controls around command execution. In this context, the shell capability is used to send authenticated requests to an external API, so undeclared execution power increases the chance of unintended data transmission.
