Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises and instructs execution of scripts with shell, file read/write, and environment access, but does not declare any permissions or capability expectations to the user. This undermines informed consent and makes it easier to hide impactful local actions such as persistence setup and file modifications behind a seemingly simple setup step.
