Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill invokes shell commands, reads local files, uploads local content, uses networked remote tool calls, and performs local writes, yet declares no permissions. This creates hidden capability expansion: users and host systems cannot accurately assess what the skill may access or modify, including local audio samples, credentials, and package files. In this context, undeclared file/network/shell access is especially risky because the skill handles sensitive biometric voice data and account-linked operations.
