Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill declares broad operational behavior including shell execution, package installation, file access, and network use, but does not expose corresponding permissions or clear user-facing authorization boundaries. That makes the bootstrap step more dangerous because a user expecting an event-discovery workflow may unknowingly approve installation and runtime-modifying actions.
