Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation instructs users to run shell commands and a setup script, and it includes examples that create or write files (for example, a batch script), yet the skill declares no permissions. This mismatch is dangerous because it obscures the skill's actual capabilities from policy and review systems, increasing the chance that file writes or shell execution occur without explicit scrutiny.
