Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly instructs users to run multiple shell commands and scripts, but no permissions are declared to signal that capability or constrain its use. This is dangerous because reviewers and users may underestimate the skill's operational reach, especially where it modifies launchd configuration, reloads agents, or invokes privileged system commands.
