Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill instructs the operator to run shell scripts (`diagnose.sh`, `fix-single.sh`, `fix-all.sh`, `restore.sh`) but does not declare any permissions for shell access. Undeclared execution capability is a real security issue because it hides the skill's operational power from reviewers and policy enforcement, making it easier for harmful or overly-privileged behavior to slip through unnoticed.
