Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill exposes effective capabilities to read/write files, access environment variables, use the network, and invoke shell commands, but does not declare those permissions. This creates a transparency and trust gap: users may authorize an image-editing skill without understanding it can access broader local and remote resources, increasing the chance of unintended data exposure or command execution through the supporting scripts.
