Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill metadata declares required binaries and an environment variable but does not declare explicit permissions, while the documented behavior clearly includes shell execution, reading local subtitle files, and writing downloaded subtitles to disk. This creates a transparency and policy-enforcement gap: users or platforms may not realize the skill can access local files, invoke external tools, and exfiltrate subtitle or local file contents to a remote API.
