Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill invokes shell scripts that perform network-capable actions against Apollo.io, but the skill metadata does not declare corresponding permissions. This creates a capability/permission mismatch that can bypass user expectations and weaken policy enforcement, especially because the scripts automatically load API credentials from local configuration and send authenticated requests.
