Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill exposes code paths that can access environment variables, local files, the network, and the shell, but it does not declare permissions or clearly constrain those capabilities. That creates a trust and sandboxing gap: users or hosting platforms may treat it as low-risk documentation while it can invoke external APIs, read/write local state, and execute helper commands such as ffmpeg.
