Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly instructs local file creation/modification and shell-based media processing, yet no explicit permissions are declared. That creates a trust and containment gap: a caller may approve a seemingly simple content skill without realizing it can write arbitrary files and invoke local tooling like ffmpeg and browser helpers.
