Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares itself as an image-retouching workflow, yet it requires broad code capabilities including shell, network, file read/write, and environment access with no explicit permissions declaration. That mismatch increases the chance that users or host systems grant powerful execution rights without understanding the real attack surface, enabling credential access, arbitrary file modification, or remote command execution if the bundled client or update path is abused.
