Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes a local Python script with shell, network, environment-variable, and file read/write capabilities, but does not declare those permissions. That creates a trust and review gap: users may authorize or run the skill without understanding that it can store credentials locally, access files, and send data to a remote API. In this context the behavior appears related to the stated image-editing workflow, but undeclared capabilities still increase the risk of unintended data exposure or misuse.
