Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill claims highly sensitive local key management but does not declare permissions while static analysis detected shell capability. Undeclared shell access in a credential-handling skill is dangerous because it can invoke arbitrary local commands, access files containing secrets, or stage exfiltration without informed user consent.
