Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill declares only the Bash tool while its documented behavior clearly requires outbound network access to call an external image-generation API. This hidden capability weakens transparency and reviewability, making it easier for a user or platform to invoke remote requests without understanding that prompts, tokens, and possibly reference-image identifiers are being sent off-platform.
