Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill explicitly documents shell command execution across multiple package managers and outbound network access, yet the metadata declares no permissions. This mismatch can cause users or orchestrators to grant trust based on incomplete capability disclosure, increasing the chance of unexpected command execution or network activity in sensitive environments.
