Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly instructs execution of shell commands, network access to Bilibili, and writing files such as `search.json` and downloaded media, yet no permissions are declared. This is dangerous because an agent or reviewer may underestimate the skill's operational reach, reducing user awareness and weakening policy enforcement around filesystem, network, and subprocess use.
