Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 81% confidence
- Finding
- The skill documents and encourages shell execution via curl and helper scripts, but no corresponding permissions are declared. That creates a transparency and policy gap: an agent or reviewer may underestimate that the skill can make authenticated external network calls and access local environment secrets such as REFLECT_TOKEN. In this context, the shell capability is especially relevant because it can exfiltrate or misuse the bearer token against the Reflect API.
