Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises and instructs use of a shell script (`scripts/flomo.sh`) but does not declare corresponding permissions, creating a capability/permission mismatch. This is dangerous because users and enforcement layers may not realize the skill can execute local commands and transmit data externally, reducing transparency and weakening review controls.
