Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares itself as a simple Douyin briefing workflow, yet it explicitly instructs use of a bundled Python client with shell execution, network access, file read/write, and credential handling. That undeclared capability expansion increases the attack surface and can mislead users or policy engines into granting trust to a package that can execute local code, persist secrets, and modify files.
