Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation exposes executable CLI entrypoints and pipeline commands using Node.js while declaring no permissions, yet the described functionality clearly implies shell execution and outbound network access to GitHub API and SkillHub. This creates a capability/permission mismatch that can mislead users or orchestration systems into granting implicit execution and network behavior without explicit review, increasing the risk of unexpected data access or command execution.
