Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill drives shell execution (`personwise`, bootstrap scripts, update commands) but does not declare permissions accordingly. That creates a transparency and governance gap: users and policy engines may believe the skill is content-only while it can install software, authenticate, and modify local state. In a skill ecosystem, undeclared execution capability is a real security issue because it weakens informed consent and permission enforcement.
