Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill explicitly instructs the agent to execute local shell-capable tooling (`python3`, `yt-dlp`) but does not declare permissions for that capability. This creates a transparency and policy-enforcement gap: a host system may fail to prompt appropriately, apply least-privilege controls, or audit execution as expected, increasing the risk of unsafe command execution on user-supplied URLs and paths.
