Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly exposes shell-executed capabilities through its CLI/module/MCP interfaces and explicitly requires external binaries such as node, git, and npm, but it does not declare any corresponding permissions or execution boundaries. This creates an authorization and review gap: consumers may treat the skill as low-risk metadata while it can invoke system tools, fetch remotes, scan repositories, and potentially perform networked package installation or command execution in CI, hooks, or MCP contexts.
