Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill exposes shell-based operational capability but does not declare permissions, which weakens transparency and informed consent for users and reviewers. In this case, the shell entrypoint is used to collect credentials, manage tokens, and invoke internal API actions, so the undeclared capability increases the risk of unexpected sensitive operations.
