Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs use of shell commands and file-writing behavior but declares no permissions, creating a capability/permission mismatch that weakens review and policy enforcement. In this context, the skill handles untrusted audio-derived content and can save artifacts to disk, so undeclared shell and file-write capabilities increase the chance of unsafe execution or data handling without explicit scrutiny.
