Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises shell-driven functionality through CLI commands and workflow descriptions, but the metadata shown does not declare corresponding permissions. Undeclared shell capability is dangerous because it obscures the true execution surface from users and reviewers, especially for a skill that can browse, audit, and install other skills via a local CLI.
