Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill declares no permissions while explicitly requiring shell execution via `curl` and `jq`. This creates a transparency and policy gap: users or hosting systems may underestimate the skill's capabilities, reducing informed consent and weakening sandboxing or review controls.
