Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill advertises local image mosaicking behavior, but the static analysis detected capabilities including environment access, file read/write, shell, and network without any declared permissions. This is dangerous because users and host systems cannot make an informed trust decision, and hidden capabilities can enable credential exposure, unauthorized file access, or unexpected external communication.
