Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs the agent to execute a shell script (`scripts/run_video_query.sh`) and requires `curl`/`jq`, but the manifest does not declare corresponding permissions. Undeclared shell capability weakens the trust boundary for users and platforms because the skill can invoke local commands and make networked API calls without transparent permission signaling.
