Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill invokes shell/CLI operations but does not declare permissions for shell access. That creates a transparency and policy-enforcement gap: a host or reviewer may believe the skill is limited to content generation while it can execute local commands, install software, and manipulate files. In this context, the hidden capability is more dangerous because the skill also performs authentication, software bootstrap, and local file handling.
