Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes a local Python script and an external binary (`yt-dlp`) through shell commands, but declares no permissions for shell execution or file access. This creates a transparency and governance gap: a host agent may permit execution without surfacing the real capabilities to users or policy controls, increasing the chance of unintended command execution against user-supplied URLs.
