Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to read files, write to job and delivery directories, and invoke shell commands such as ffmpeg, ffprobe, Python, and bundled scripts, but no declared permissions are provided to bound those capabilities. Although the skill text includes safety-oriented scope restrictions, those are only prompt-level constraints and do not replace an enforceable permission model, so a host may grant broader access than intended.
