Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill claims to be read-only and to require no credentials, but its instructions clearly invoke shell commands, read local files, and make network requests to user-supplied URLs and referenced HLS segments. That capability mismatch is security-relevant because it can hide the real trust boundary from the permission model and enable SSRF, local file access, or command execution paths without explicit declaration and review.
