Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares no permissions even though it clearly instructs use of a shell-executed external binary (`wacli`) and references environment-dependent state such as `~/.wacli`. Hidden or undeclared shell capability is dangerous because it can surprise the host platform's trust and permission model, enabling message sending, history access, and account sync without transparent authorization boundaries.
