Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documentation describes invoking a local Python script that reads image files or URLs, uses environment variables for cloud credentials, and sends data over the network to Google Vertex AI, yet no permissions are declared. This creates a transparency and policy-enforcement gap: an agent or reviewer may underestimate the skill's ability to access local files, secrets, and external services, increasing the chance of unintended data exfiltration from sensitive images or URLs.
