Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill demonstrates file write behavior by downloading media to local paths like './video.mp4', './audio.mp3', and playlist outputs, but it does not declare corresponding permissions. Undeclared file capabilities reduce transparency and can cause an agent to invoke the skill without understanding that it will create or overwrite local files.
