Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill invokes shell scripts and instructs users to run bash commands, but the metadata does not declare any corresponding permission or capability beyond a generic requirement on bash. This under-declares the operational power of the skill, which can mislead reviewers and users about execution risk and reduce effective policy enforcement.
