Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill embeds executable workflows that use environment variables, local file I/O, network access, and shell-adjacent tooling (for example ffmpeg) without declaring permissions or clearly constraining those capabilities. This creates a hidden trust boundary: a user or host may believe the skill is only a planning/template tool, while it can actually access sensitive local resources and invoke external services that may incur cost or expose data.
