Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill clearly instructs the agent to invoke shell commands (`ppt2fig`, `ppt2fig-cli`, and `python ... run_ppt2fig.py`) on user-supplied file paths and arguments, but no explicit permissions are declared. This creates a real security gap because an orchestrator or reviewer may underestimate the skill's execution capabilities, and any unsafe interpolation or future modification could turn this into command execution abuse or unintended local file access.
