Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill directs use of shell scripts that can install software, modify browser profiles, and write files, yet it declares no permissions. That mismatch prevents meaningful user consent and weakens sandboxing or policy enforcement, especially because the flow includes browser installation, extension deployment, and account-login steps.
