Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation indicates it reads local files, invokes Python/shell commands, and sends data over the network, but it does not declare corresponding permissions. This creates a transparency and least-privilege problem: users and host frameworks may not realize that local images and extracted sensitive personal data are transmitted to an external OCR service.
