Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill invokes shell scripts (`bash .../upload.sh` and `bash .../download.sh`) and requires `curl`, but it does not declare any permissions corresponding to shell/code execution. This creates a capability mismatch that can bypass policy review and least-privilege controls, making the skill more dangerous because it performs file and network operations against user-supplied paths and identifiers.
