Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill documentation directs the host agent to read and write local files, run Python scripts, pass environment variables, and optionally handle http(s) video URLs, but the skill declares no permissions or capability boundaries. This creates a trust gap where a host may enable broader file, shell, env, and possible network access than the user realizes, increasing the chance of over-privileged execution or misuse if the surrounding tooling does not enforce least privilege.
