Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises and instructs use of shell commands and writes a persistent registry file, but does not declare any permissions. Even though the behavior appears aligned with the skill's purpose, undeclared shell and file-write capabilities create a trust and containment gap: an agent or platform may permit actions the user did not explicitly approve, including overwriting arbitrary paths via `--file` or writing redirected output such as `> shutoff-card.txt`. In this context the content is not overtly malicious, but the missing permission declaration is still a real security issue because it weakens transparency and policy enforcement.
