Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares install scripts, shell commands, environment-variable configuration, and plugin hooking behavior, but does not declare corresponding permissions. That creates a transparency and policy-enforcement gap: reviewers or platforms may underestimate what the skill can do during install and runtime, especially because it can execute shell-based installation and influence command execution paths.
