Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill advertises shell-based behavior and environment access but does not declare permissions, which weakens reviewability and informed consent for a package that monitors host activity and posts externally. In this context, hidden shell/env capability is security-relevant because the skill handles system metrics and likely secrets-adjacent configuration, so undeclared capability increases the chance of unsafe execution or policy bypass.
