Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs execution of shell commands, Node scripts, curl, ffmpeg, and browser automation, yet no permissions are declared. That creates a transparency and trust problem: a user or platform may treat the skill as lower-risk than it really is, while it can perform local command execution and network access. In this context, undeclared shell/env capability is materially dangerous because the workflow includes downloading files, invoking external tools, and interacting with browser debugging interfaces.
