Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises network/image-download functionality and likely reads local Markdown input, but the metadata shows no declared permissions. Undeclared file and network capabilities are a security transparency problem because users and enforcement systems cannot accurately assess or constrain what the skill may access. In this context, remote image downloading also increases exposure to SSRF-like fetches, unexpected external requests, and data handling risks if not explicitly permissioned and documented.
