Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill includes executable shell workflows but declares no corresponding permissions, creating a capability/permission mismatch that can cause unsafe execution without appropriate review or user awareness. In this context, the undocumented shell capability is more concerning because the skill performs network requests and guides automated interaction with protected sites.
