Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to invoke local shell commands and references file-writing outputs, but the manifest does not declare corresponding permissions. This creates a capability/visibility gap: a host may load the skill assuming low privilege while the documented workflow actually performs command execution, environment use, and output file creation.
