Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill clearly instructs execution of shell scripts that can create macOS users, verify shell state, and write rollout receipts, yet it declares no permissions. That mismatch is dangerous because it obscures the true capabilities of the skill from any permission-review or policy-enforcement layer, increasing the chance that administrative changes and file writes occur without explicit scrutiny.
