Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill performs network access to a third-party OCR service and includes code that writes image data into an in-memory buffer, yet the skill metadata declares no permissions or safety disclosures. This creates a transparency and governance gap: users and hosting platforms may not realize local image contents are being transmitted off-device, which can expose sensitive documents or screenshots.
