Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs users to run shell commands, install packages, register an MCP server, and execute Python-based tests, but it does not declare corresponding permissions or capabilities. In a skill ecosystem, this mismatch weakens transparency and consent boundaries: users or orchestrators may not realize the skill can drive shell, environment-variable, and file-writing behavior, increasing the risk of unintended local changes or command execution.
