Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation shows access to environment secrets, local file I/O, network access, and shell execution, but no permissions are declared to make those capabilities explicit. This is dangerous because users and hosting platforms cannot accurately assess or constrain what the skill can do, especially given it reads credentials, uploads user-provided files, writes outputs to disk, and invokes ffplay as a subprocess.
