Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill performs shell-capable actions but does not declare permissions or constrain those capabilities. This reduces transparency and makes it easier for an agent or reviewer to underestimate that the skill can execute commands against a remote router, increasing the chance of unsafe use.
