Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation advertises executable setup and CLI commands (`bash setup.sh`, `nex-meetcost ...`) and describes capabilities including local SQLite storage, but it declares no permissions. This creates a real transparency and enforcement gap: users or hosting platforms may believe the skill is passive while it can invoke shell commands, read environment context, and write local files/database content.
