Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly instructs the agent/user to run shell commands, install software, invoke Python, curl endpoints, and use ffmpeg, yet it declares no permissions to reflect those capabilities. This mismatch weakens policy enforcement and user understanding, making it easier for a seemingly harmless skill to trigger command execution paths without explicit authorization boundaries.
