Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises capabilities to launch and manage persistent Cursor/tmux jobs, which inherently implies shell execution, environment access, and likely file read/write, but it declares no permissions or trust boundaries in the skill metadata. This creates an authorization and transparency gap: users and the host system are not explicitly warned that the skill can start background processes and affect local state.
