Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to execute shell commands, install software over SSH, fetch and run a remote installer via curl, and modify local configuration files, yet no permissions are declared. This creates a serious trust and policy gap: the skill appears less privileged than it really is, which can lead to unsafe execution, insufficient user consent, and bypass of platform permission controls.
