Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill directs the agent to use environment variables, read local files, write outputs, and make network calls, but it does not declare any permissions. This creates a governance and transparency gap: an orchestrator or reviewer cannot accurately assess or constrain what the skill is allowed to access, increasing the risk of unintended file access, secret use, or outbound data transfer. In this context, the capability set is expected for an image-generation wrapper, so the issue is not inherently malicious, but it is still a real security control failure.
