Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises and demonstrates shell execution via installation and script invocation, but does not declare corresponding permissions. This creates a transparency and policy gap: users or hosting agents may permit the skill under the assumption it has no execution capability, while it actually relies on shell commands that can perform network operations and local process execution.
