Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documentation advertises scripts that read input files and write output images or batch results, but no permissions are declared to reflect those capabilities. This creates a transparency and governance gap: users or platforms may authorize the skill without understanding that it can access local files and persist generated or decoded data to disk.
