Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises and relies on shell execution, environment access, and file read/write behavior, but it does not explicitly declare permissions. That creates a transparency and policy-enforcement gap: users or orchestrators may invoke the skill without understanding that it can download media, access API keys, and write files to disk.
