Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill exposes shell, network, file read/write, and environment access but does not declare permissions, preventing users and policy systems from understanding its effective capabilities. This is dangerous because hidden capabilities can enable data exfiltration, local file access, or command execution beyond the user’s expected image-generation workflow.
