Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill invokes shell execution via curl but does not declare corresponding permissions, creating a capability/permission mismatch. This weakens user and platform transparency and can lead to unexpected external network activity under the guise of a documentation-only skill.
