Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation indicates the tool depends on external Baidu OCR APIs and therefore has network capability, but no explicit permission/notice is declared for that behavior. This creates a transparency and policy gap: users may invoke the skill expecting local OCR processing while their data is actually transmitted off-host to a third party.
