Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to read and write local files and to fetch remote images, but it declares no permissions or user-facing consent boundaries. That mismatch is dangerous because users and the hosting platform may not realize the skill can persist session data locally and make network requests, increasing the risk of unauthorized data handling or SSRF-style abuse through attacker-supplied image URLs.
