Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises and documents file-reading behavior (screenshots, image metadata/cropping, cleanup analysis) but does not declare corresponding permissions. Undeclared file access weakens policy enforcement and user awareness, making it easier for the skill to read local files or process sensitive screenshots without explicit authorization boundaries.
