Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 79% confidence
- Finding
- The skill documents shell and network-capable behavior (curling an external API) but does not declare any permissions. That creates a transparency and policy-enforcement gap: an agent may be allowed to exfiltrate user-provided address or location data and use shell execution without an explicit permission review.
