Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill declares no permissions, yet the documentation clearly includes shell-capable behavior via script execution and command invocation such as running bash wrappers and system tools. This creates a trust and containment gap: operators may approve or route the skill as low-risk while it can actually invoke local commands and tooling.
