Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises executable behavior that uses environment variables, shell commands, and file read/write via `scripts/rewriter.sh`, but it does not declare permissions explicitly. This can undermine platform trust and informed consent because users and policy layers may not realize the skill will access local files, invoke shell tooling, and transmit content off-host using an API key.
