Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 80% confidence
- Finding
- The skill documentation advertises shell-based installation and setup behavior, but no explicit permissions are declared for shell execution. This creates a transparency and least-privilege problem: users and hosting platforms may underestimate that the skill can invoke system-level commands, including installers and schedulers.
