Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises shell-capable bundled resources (`scripts/vm_api.sh`) and operational behavior that can provision and destroy infrastructure, but it does not declare any explicit permissions. This creates a transparency and governance gap: callers may invoke a skill with infrastructure-changing capabilities without an auditable permission boundary, increasing the chance of unintended execution or misuse.
