Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs users to execute local shell scripts, but the manifest does not declare permissions or clearly surface that shell execution is part of its operational model. This creates a transparency and trust-boundary issue: consumers may invoke code-capable behavior without explicit permission metadata, increasing the risk of unintended execution in environments that rely on declared capabilities for review or policy enforcement.
