Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises only product-image generation, but the provided commands invoke a Python script with shell execution, package installation, file access, environment access, and likely networked API calls, while no permissions are declared. This creates a trust-boundary problem: users and reviewers cannot accurately assess what the skill may access or modify, increasing the risk of unexpected data exposure, filesystem changes, or command execution.
