Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
- The skill advertises shell-based installation/setup behavior via referenced scripts, but the manifest does not declare permissions accordingly. This weakens user awareness and platform policy enforcement because a user may install a skill expecting a simple bundle while local script execution occurs during setup.
