Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 76% confidence
- Finding
- The skill advertises executable shell-based behavior and dependency installation guidance but does not declare corresponding permissions, creating a mismatch between stated capability boundaries and actual execution potential. This can weaken policy enforcement and user understanding, especially because the skill performs network-facing monitoring with curl and scripted execution.
