Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly instructs the agent or user to perform network operations against an external Immich instance, but there is no declared permission boundary or explicit capability declaration in the skill metadata. That creates a security and governance gap: the skill can initiate authenticated requests to a remote service without transparent permission scoping, increasing the risk of unintended data access or modification.
