Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly uses shell commands, environment variables, local file paths, and network calls, but does not declare permissions accordingly. This hides the real execution capabilities from users and reviewers, making consent and risk evaluation ineffective for a skill that can publish content, handle media, and interact with external services.
