Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documentation indicates capabilities to read local files and access remote URLs, but it does not declare permissions or prominently scope those behaviors. This can mislead users about what data the skill may access and transmit, especially because local video files may contain sensitive content and remote URL handling introduces external network access.
