Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly enables shell-capable device control through ADB commands, yet the metadata shown in the skill file does not declare corresponding permissions or execution boundaries. This is dangerous because it hides the true capability surface of the skill and allows real-device actions on a connected phone without transparent permission signaling or policy checks.
