Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation shows capabilities that rely on environment variables and shell execution, but it does not declare corresponding permissions. This creates a transparency and policy-enforcement gap: users or orchestrators may invoke the skill without realizing it accesses secrets from the environment and runs command-line tooling such as Python and FFmpeg.
