Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill exposes shell, file, environment, network, and write capabilities through documented commands, yet no explicit permissions are declared. This creates a transparency and policy-enforcement gap: a user or host may assume the skill is low-risk while it can install packages, access local files, and communicate externally. In this context, the risk is elevated because the skill invokes a general Python helper that appears able to route tasks to external AI services and handle local media inputs.
