Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares no permissions while explicitly embedding shell-based install commands and describing execution of an external binary. This mismatch can mislead users or enforcement systems about the skill's actual capability boundary, increasing the chance of unsafe approval or execution in environments that rely on declared permissions.
