Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to use shell-accessible commands such as `scripts/nblm.sh` and `notebooklm-mcp-setup-auth`, but the metadata does not declare corresponding permissions or execution requirements. This creates a capability/consent gap: an agent or user may invoke local commands, open browser-based auth flows, or contact local services without explicit permission signaling, which is a real security and trust issue even though the commands appear related to the skill’s stated purpose.
