Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to invoke shell-capable commands (`command -v`, `python3`, and indirectly `ffmpeg`/`ffprobe`) but does not declare any `permissions` or `allowed-tools` scope. That creates an authorization gap where an agent may execute shell actions without an explicit least-privilege boundary, increasing the risk of unintended command execution or policy bypass if the skill is reused in broader contexts.
