Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation describes executing a Python script that reads local files, writes output artifacts, and calls a remote video-generation service, but the skill declares no permissions. This creates a transparency and policy-enforcement gap: a host may allow the skill under the assumption it is low-privilege, while it actually requires filesystem, environment, and network access to process inputs and contact external APIs.
