Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly instructs the use of shell commands (`curl`, `ffmpeg`, `ffprobe`, `python3`, `say`) but does not declare corresponding permissions. This creates a transparency and policy-enforcement gap: an agent may execute networked shell actions and access local configuration/secrets without users or the platform having an explicit permission boundary.
