Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill exposes shell, file, environment, and network capabilities without declaring permissions, which prevents users or the platform from understanding the true execution and data-access scope before use. In this context, the skill uploads images to an external service and initializes local configuration, so undeclared capabilities materially increase the risk of unexpected data exfiltration, local file access, or side effects.
