Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill invokes shell commands, reads local image files, writes outputs, accesses environment variables via $SKILL_PATH, and performs networked API operations, yet no permissions are declared. This creates a trust-boundary problem: users and orchestrators cannot accurately assess or constrain what the skill can access, increasing the risk of unintended file exposure or external data transfer.
