Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documents shell-based network actions but declares no permissions, which creates a transparency and policy-enforcement gap. In an agent environment, undeclared shell capability can enable outbound requests and data handling beyond what a reviewer or runtime policy expects.
