Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to execute multiple shell scripts and interact with a localhost service, but it declares no permissions or trust boundary information. This is dangerous because shell execution materially increases attack surface: a compromised local service, modified scripts, or attacker-influenced arguments such as video URLs could lead to command execution, data access, or unintended local actions without the user understanding the risk.
