Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly instructs users to execute shell commands and relies on shell scripts, yet the metadata only declares a binary requirement and does not transparently declare the effective shell capability. This weakens permission transparency and reviewability, increasing the chance that users enable a skill without understanding that it can modify local configuration and automation state.
