Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill directs the agent to read and write local files and execute shell commands (`yt-dlp`, `ffmpeg`, Python scripts, site build steps) but does not declare permissions or boundaries for those capabilities. This is dangerous because hidden or undeclared execution and filesystem access reduces user visibility and weakens policy enforcement, increasing the chance of unintended file modification or command execution beyond the expected task.
