Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill advertises a document-processing workflow but includes capabilities implying file access, shell execution, network access, and file writing without any declared permissions or clear user-facing constraints. This expands the attack surface because helper scripts, transcription backends, and remote dataset interactions could access local files or external services in ways the user did not explicitly authorize.
