Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises executable workflows that use environment variables, file operations, network access, and shell tools, but it does not declare permissions or capability boundaries. This weakens reviewability and consent, and can lead to the agent invoking sensitive actions such as reading local files, calling external APIs, or running ffmpeg/python commands without clear upfront authorization.
