Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to execute a local Python script and mentions additional image-generation behavior that may read environment variables, inspect workspace files, enumerate installed skills, invoke external binaries, and write a PNG file, yet no permissions are declared. This creates a trust and review gap: operators may approve or install the skill without realizing it needs shell, file read, file write, and environment access, increasing the chance of unintended data exposure or unsafe execution in sensitive workspaces.
