Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill invokes a shell script and requires command-line tools, but it does not declare permissions for shell execution. That creates a transparency and policy-enforcement gap: users or orchestrators may not realize the skill can execute local commands, reducing auditability and increasing risk if the script is later modified or misused.
