Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- The skill advertises only basic metadata while exposing execution capabilities such as shell use, environment-variable access, and file-writing workflows through documented commands and configuration changes. Undeclared capabilities reduce informed consent and make it easier for a user or platform to invoke code with broader side effects than the description suggests.
