Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill explicitly orchestrates shell execution through tmux, bash, and Claude Code, yet the metadata declares only binary requirements and no permissions/capability boundary. That mismatch is dangerous because an orchestrator or user may treat the skill as lower-risk than it is, even though it can execute arbitrary shell commands in the project context via `send-keys` and `--dangerously-skip-permissions`.
