Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documentation shows shell execution capability via `python3 scripts/garden_doctor.py ...` examples, but no permissions are declared. Undeclared execution capabilities reduce transparency and can cause an agent platform or reviewer to underestimate what the skill can do, which becomes risky if the underlying script later executes commands, reads files, or accesses the environment.
