Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documents shell-based capabilities and network interactions but does not declare corresponding permissions. In a plugin/skill ecosystem, undeclared capabilities reduce transparency and can cause operators to install a skill without understanding that it will make outbound requests and use shell commands, increasing supply-chain and data-exfiltration risk.
