Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly instructs the agent to execute local scripts, read from the user's home directory, interact with the Clash controller over the network, and install/remove launchd jobs, yet it declares no permissions. That mismatch weakens user awareness and policy enforcement, because a consumer of the skill cannot accurately assess that it can run shell commands, access files, and make persistent system changes.
