Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill explicitly installs a startup hook and executes arbitrary shell scripts from a watched directory, yet the metadata does not declare permissions corresponding to shell execution or environment access. That gap is dangerous because it obscures the true trust boundary: any script dropped into the directory will run as the gateway user, making review and consent incomplete.
