Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation contains shell-capable examples (`curl`, pipes, `grep`, `jq`) but does not declare corresponding permissions. In an agent ecosystem, undeclared execution/network capabilities reduce transparency and can cause users or orchestrators to invoke outbound requests and shell processing without explicit consent or policy review.
