Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly invokes shell commands and automation workflows but does not declare the permissions required for those capabilities. This is dangerous because it hides the true execution and trust boundary from users and reviewers, especially for a tool that can launch calls, install helper apps, and drive macOS Accessibility automation.
