Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill clearly instructs the agent to execute shell scripts (`cli-state.sh`, `run-cli.sh`) and other shell-based setup flows, yet no permissions are declared. This creates a capability/consent gap: users and the hosting platform may not realize the skill can invoke local shell commands, install software, or mutate local state.
