Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly performs shell-capable actions such as `npm install -g`, `systemctl --user`, reading and rewriting systemd unit configuration, restarting a live service, and rolling back state, yet it declares no permissions. This creates a dangerous mismatch between the skill's stated metadata and its actual capabilities, reducing user visibility and policy enforcement around privileged operational changes.
