Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises and demonstrates code paths that can read environment variables, access local files, invoke shell/ffmpeg, write files, and make network requests, yet no explicit permissions are declared. That creates a trust and enforcement gap: a host or reviewer may assume the skill is low-privilege while it can handle sensitive inputs like API keys, local media, and outbound uploads. In this context, the combination is more dangerous because the workflow explicitly asks users to export API keys and pass absolute file paths for media operations.
