Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill invokes local Python scripts, installs dependencies, reads input images, may write outputs, accesses environment variables via shell execution context, and sends data to a remote API, yet it declares no permissions. This creates a mismatch between the skill's documented trust boundary and its actual capabilities, preventing users or the platform from making informed security decisions about network exfiltration, file access, and command execution.
