Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares no permissions while explicitly invoking shell commands via bash scripts and requiring external binaries like nc and curl. This creates a capability/permission mismatch that can bypass expected security review and runtime controls, especially because the skill performs network connectivity checks against arbitrary host:port targets.
