Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill documentation exposes capabilities that imply shell execution, network access, and possible environment usage, but it declares no permissions or equivalent user-visible disclosure. That mismatch weakens trust boundaries and can cause an agent or user to invoke the skill without understanding that local commands and remote calls may occur.
