Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill embeds and instructs execution of substantial shell code but does not declare any permissions for shell access. This creates a transparency and governance gap: reviewers and runtime policy engines may treat the skill as lower risk than it actually is, while the skill can still read files, persist credentials, and make network calls.
