Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises and demonstrates code paths that use environment variables, filesystem access, shell execution, and network calls, yet no explicit permission model is declared. That creates an unclear trust boundary: an invoking agent or reviewer may treat the skill as low-risk content analysis while it can actually upload files, call external APIs, and run local tooling like ffmpeg. In this context, the danger is amplified because the workflow includes handling user-supplied media and API keys, which are sensitive assets.
