Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill clearly instructs the agent to execute shell commands (`bash`, `find`, `xargs`, `gs`, Python scripts), yet the metadata declares no permissions. That mismatch is a real security issue because it obscures the skill's operational capabilities from any permission or review layer, increasing the chance of unintended command execution without explicit user understanding or platform enforcement.
