Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill advertises shell/env-related capabilities via its installation instructions, but does not declare corresponding permissions. This weakens user consent and reviewability because users may run shell commands or provide environment-backed secrets without clear upfront disclosure.
