Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill clearly instructs the operator to run shell commands and use scripts that can modify system state, but it declares no permissions. That mismatch is a real security issue because downstream systems or users may treat the skill as lower-risk than it actually is, despite it enabling package installation, service control, and privileged configuration changes on a macOS host.
