Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs users to run shell commands, create directories, and invoke local scripts, yet it declares no explicit permissions. This undermines informed consent and policy enforcement because users and platforms cannot easily see that the skill needs shell execution and filesystem access before installation or use.
