Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation instructs users to invoke `scripts/moderate.sh`, which implies shell execution capability, but no permissions are declared. This creates a trust and enforcement gap: a platform or reviewer may treat the skill as low-privilege while it actually depends on command execution and outbound API use, increasing the risk of unexpected script execution or policy bypass.
