Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill requires shell execution (`curl`, `jq`, `md5sum`) but does not declare corresponding permissions, creating a capability/permission mismatch. That increases the chance the skill will run commands and handle local files or network data without clear user-facing authorization boundaries.
