Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs agents to run a bundled Bash CLI (`scripts/massive`) and shell commands, but the manifest shown in SKILL.md does not declare any corresponding permissions. Undeclared shell capability increases risk because downstream systems or reviewers may treat the skill as less privileged than it really is, reducing scrutiny around command execution, network access, and secret handling.
