Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares only Bash tooling and does not disclose any network permission or external data transfer, yet its documented usage clearly depends on an external API token and remote image generation service. This creates a transparency and consent problem: users may invoke the skill without understanding that prompts, tokens, and possibly reference-image identifiers will be sent to a third party.
