Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill invokes shell scripts and operational CLI commands that can inspect and modify the host, but it does not declare corresponding permissions. This creates a mismatch between the skill's effective capabilities and its stated trust boundary, increasing the risk of silent privileged execution and unsafe deployment in environments that rely on permission metadata.
