Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly instructs the agent to use shell commands, read environment/tool availability, and read/write files, but it does not declare those permissions. That mismatch is dangerous because it hides the skill's true execution capabilities from the permission model and from users reviewing what the skill can do.
