Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises executable shell usage and file read/write behavior via its quick-start commands and claim-letter generation, but it declares no permissions. That mismatch is a real security issue because an agent or platform may expose capabilities the skill implicitly relies on without giving users or reviewers clear visibility into local file access and command execution risk.
