Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares itself as a narrowly scoped image-generation workflow, but the documented execution path installs dependencies and invokes a local Python script that appears to have shell, filesystem, environment, and network capabilities without any explicit permission declaration. That mismatch increases the chance of overprivileged execution, hidden side effects such as config writes or data exfiltration, and unsafe use by operators who expect a simple prompt template rather than executable automation.
