Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the user to run Python, install Pillow, read Markdown from disk, write rewritten Markdown and image files, and download remote HTTP(S) images, yet it declares no permissions. This is dangerous because users or policy systems may approve or execute the skill without understanding that it performs filesystem access and outbound network activity, which can enable unintended data exposure, SSRF-like access to internal endpoints, or unsafe overwrites if the script is misused.
