Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to invoke shell commands and write output files, but it does not declare permissions for those capabilities. This creates a permission-model mismatch: an orchestrator or reviewer may assume the skill is low-risk while it can actually execute local commands such as Python, ffmpeg, npm, and cp, potentially affecting the filesystem and triggering dependency installation or external tool execution.
