Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill exposes code paths that can access environment variables, the filesystem, the network, and the shell, yet it declares no permissions or capability boundaries. That creates a confused-deputy risk: an invoking agent or reviewer may treat it as low-privilege content while it can actually perform sensitive actions such as reading local files, invoking ffmpeg, or making outbound API calls.
