Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares no required permissions while its documented behavior includes environment-variable access, reading and writing local files, and downloading remote resources. This is dangerous because agents or users may invoke it assuming a low-privilege local conversion tool, when it actually performs network access and persistent filesystem changes, reducing transparency and informed consent.
