Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises execution of local Python/FFmpeg scripts and use of environment variables, but it does not declare corresponding permissions. This creates a capability/permission mismatch that can bypass user and platform expectations about shell execution and environment access, increasing the risk of unintended file processing or command execution in a local context.
