Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises no declared permissions, yet its documented execution path invokes Python scripts that can access the environment, filesystem, shell, and network. This creates a trust boundary problem: users and reviewers may assume a narrow image-editing capability while the skill can perform broader actions, increasing the chance of unexpected data access, exfiltration, or command execution if the backing script is unsafe or compromised.
