Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes a local Python script and an external binary (`yt-dlp`), which gives it shell execution and file-read capabilities, yet it declares no explicit permissions or guardrails. This is dangerous because ambiguous or undeclared capabilities reduce policy enforcement and user visibility, increasing the chance the skill is invoked in contexts where code execution or local file access was not expected.
