Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to read and write project files and to execute local shell commands such as opening HTML files, invoking Python scripts, ffmpeg, and npx. Those capabilities are operationally relevant to the skill, but they are undeclared, which creates a permission-transparency gap: a user or orchestrator cannot accurately assess or constrain what the skill may do before execution. In this context the commands are mostly local and workflow-oriented rather than overtly exfiltrative, but hidden shell/file capabilities still increase risk if the skill or its dependencies are modified or abused.
