Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly instructs the agent to invoke shell, bash, ssh, curl-like API interactions, and Node scripts, yet it does not declare corresponding permissions. That creates a capability/permission mismatch where reviewers or enforcement systems may underestimate what the skill can do, especially since it also handles inherited secrets and remote execution in a sandbox context.
