Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill invokes shell scripts but does not declare corresponding permissions, creating a transparency and governance gap between what the skill claims and what it can actually do. In a credentialed skill that reads X2C_API_KEY and queries private dashboard data, undeclared shell capability increases the chance of unreviewed command execution paths and weakens user/admin ability to assess risk.
