Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation declares runtime requirements and clearly implies capabilities to read local videos, write subtitle and backup files, access environment variables, and invoke tooling such as ffmpeg, but it does not declare corresponding permissions. This creates a transparency and policy gap: users or platforms may underestimate what the skill can access and execute, increasing the risk of unintended file access or shell execution in a local environment.
