Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the user to run a bundled shell script against a target path, which implies file-read capability, but no corresponding permissions are declared. This mismatch can bypass user expectations and platform review signals, and in this specific context is more suspicious because the skill explicitly aims to make a package look 'less suspicious' and 'normal in review,' which can facilitate concealment of risky contents.
