Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill instructs use of shell commands and bundled scripts, but the metadata shown in this file does not declare the corresponding permissions. Undeclared execution capability is dangerous because it can bypass expected review and consent boundaries, especially in a skill that handles authentication secrets and invokes local tooling.
