Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises and depends on capabilities including environment access, file reads/writes, and shell execution, but does not declare permissions. That creates a transparency and policy-enforcement gap: an agent or reviewer may activate a skill with more power than expected, increasing the chance of unsafe file operations, command execution, or data exposure. In this context the risk is elevated because the skill explicitly runs a local server, invokes Python/uvicorn/ffmpeg workflows, persists uploaded files, and writes output to user-accessible paths.
