Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises and documents shell-capable operations such as `xurl` CLI commands and spawning subagents, but no explicit permissions model is declared in the skill metadata. That mismatch can enable unintended command execution pathways or broaden the effective capability surface without clear user or platform controls, especially in an auto-triggering skill.
