Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill explicitly instructs the agent to execute shell commands and access locally stored credentials, yet it does not declare any permissions for shell or environment access. This creates a transparency and policy-enforcement gap: users and the platform may not realize the skill can launch processes, read secrets from Keychain-backed flows, and invoke local scripts that affect Spotify state.
