Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documentation instructs use of network access, shell execution, environment variables, and file read/write behavior, but no explicit permissions are declared. That mismatch can prevent users or a hosting platform from understanding the actual trust boundary, especially because the skill uploads local audio/video or remote URL content to a third-party API and may write outputs or config files. In this context the capabilities are expected for ASR, but the undeclared scope still increases risk through under-disclosure rather than overtly malicious behavior.
