Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes shell scripts, reads and writes state files, and expects persistent OS-level integration, yet no permissions are declared. That creates hidden capability expansion: an operator may install or trust the skill as low-risk while it can execute commands and manipulate local files. In this context, the mismatch is more dangerous because the skill is positioned as a generic UX helper suitable for all channels, which encourages broad deployment.
