Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill declares no permissions while explicitly instructing use of shell scripts such as ./scripts/post.sh and requiring local binaries like curl and node. This mismatch can cause users or security tooling to underestimate the skill's execution capabilities, increasing the chance of unreviewed command execution and unsafe use in agent environments.
