Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill invokes shell commands, reads and writes local files, accesses environment variables, and performs network requests, yet no permissions are declared. This creates a transparency and policy gap: a caller or platform may treat the skill as low-risk while it can upload images, use API keys from the environment, and write artifacts locally. In this context, the risk is elevated because the skill explicitly interacts with a remote API and handles user-provided images and prompts, which can expose sensitive data if operators are unaware of its effective capabilities.
