Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill exposes shell and environment-driven execution paths but does not declare permissions, which weakens reviewability and informed consent for a capability that can execute local commands. In this context, the skill is explicitly a router for running triggers and scripts, so the behavior is expected, but the missing declaration still creates a real security transparency gap that could lead users or higher-level policy systems to under-scope the risk.
