Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill declares shell-based capabilities through setup and helper scripts but does not explicitly declare permissions for shell execution. This weakens the security boundary and can cause the platform or user to underestimate the skill's ability to read secrets, invoke local tools, and make authenticated network requests.
