Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 79% confidence
- Finding
- The skill declares a required shell script file (`scripts/search.sh`) and therefore has code-execution capability, but no explicit permissions are declared to inform or constrain that behavior. This creates a trust and review gap: operators may install a skill that can invoke shell/network actions without clear permission metadata, increasing the chance of unexpected command execution or secret handling.
