Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill declares no permissions while its instructions clearly rely on shell execution and environment access, which creates a transparency and policy-enforcement gap. In practice this can let a seemingly simple retrieval skill run commands and touch auth-related state without adequate review or user awareness.
