Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to execute shell scripts and create a local credential file, but the skill declares no permissions. That mismatch is a real security issue because it obscures the skill's actual capabilities, reducing user awareness and policy enforcement around shell execution and file writes that handle sensitive API keys.
