Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill invokes Python and writes transcription outputs to disk, but it does not declare corresponding permissions or capability requirements beyond `python3`. This creates a transparency and policy-enforcement gap: users and the platform may not realize the skill will execute shell commands, write files, and potentially trigger model downloads/network access at runtime.
