Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises content creation but includes capabilities to read environment variables, access local files, and perform network operations without declaring permissions. This creates a transparency and consent gap: an agent or user may invoke the skill expecting text/image generation while it can also access credentials and communicate externally.
