Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation instructs users to run shell commands such as npm install, node execution, and schtasks creation, yet the skill declares no permissions. This creates a transparency and trust problem: users and enforcement layers may not realize the skill requires command execution and scheduled task creation, which expands the attack surface and can enable unintended system changes.
