Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill instructs the agent to run shell commands, access environment-backed credentials, read local image inputs, write generated outputs, and make outbound network requests, yet it declares no permissions. That mismatch weakens sandboxing and user transparency: an agent may gain broader-than-expected access to files or secrets while contacting an external API, which is especially risky in a skill that processes user-supplied assets.
