Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill explicitly instructs use of shell commands and bundled scripts (`./scripts/zqcc.sh`, `curl`, `jq`) but does not declare corresponding permissions or execution capabilities. Undeclared shell capability weakens policy enforcement and review because a host may expose command execution paths that users and security controls were not clearly told this skill needs; in this skill, that shell access is used with a paid secret (`ZQCC_APP_KEY`), increasing the risk of credential exposure or unintended outbound requests if the script behavior changes or is compromised.
