Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill clearly instructs use of shell scripts (`check-connection.sh`, `reporead-api.sh`) but does not declare corresponding permissions. Undeclared shell capability weakens user and platform visibility into what the skill can execute, increasing the risk of unexpected command execution or unsafe handling of secrets such as the API key.
