Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documentation describes capabilities that require network access and shell execution, yet no explicit permissions are declared. That creates a transparency and consent gap: a user or platform may approve the skill without understanding it invokes external APIs and local tooling like FFmpeg/subprocesses. In this context, hidden network and shell capability is more dangerous because the skill also asks for API keys and handles audio/microphone-related workflows.
