Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs the user to execute a local Node.js script via shell (`node .../extract.js <URL>`), but the skill metadata does not declare the shell capability/permission. This creates a transparency and policy gap: a caller or platform may treat the skill as low-risk while it actually requires command execution and network-driven processing of untrusted URLs.
