Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill exposes shell execution capability through documented bash invocations but does not declare corresponding permissions. Undeclared execution capability reduces transparency and can bypass user or platform expectations about what the skill is allowed to do, increasing the risk of unintended command execution or misuse of inherited environment secrets.
