Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documentation includes shell commands that download and extract content from a remote GitHub archive into the local skills directory, which implies shell execution plus file write capability without any declared permissions boundary. In a skill ecosystem, undeclared install-time write and shell behavior increases supply-chain risk because users may treat the skill as passive documentation/API usage when it can alter the local environment.
