Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to execute shell commands and write output files, but it declares no corresponding permissions. That creates a hidden capability gap where users or the platform may not realize the skill can install packages, download content, and create artifacts on disk. In this context, the risk is increased because the workflow includes dependency checks, optional installation commands, downloads, and file generation, all of which should be explicitly permission-gated.
