Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documentation instructs the agent or user to run shell scripts, but the skill metadata shown here does not declare corresponding permissions. Undeclared shell capability reduces transparency and can bypass a permission-gating model, making it harder for users and the platform to understand that local command execution is involved.
