Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to run Python scripts and shell tools like ffmpeg/ffprobe against user-supplied paths, but it declares no permissions. That mismatch is a real security issue because it hides file-read and command-execution capabilities from the permission model and review process, increasing the chance of unintended local file access or unsafe command use.
