Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly instructs users to run installer and fix scripts that clone repositories, modify session/config files, and write launchd plist state, yet it declares no permissions. This creates a permission-transparency gap: users and tooling are not properly warned that the skill performs persistent file modifications and installs a daemon, which increases the chance of unsafe execution.
