Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation instructs the agent to run multiple shell scripts that perform registration, authentication recovery, profile editing, and network-backed onboarding flows, yet the skill declares no permissions. This creates a capability/permission mismatch: a user or platform may trust the skill as low-privilege while it actually requires shell, file access, and network operations that can handle sensitive auth material and modify local state.
