Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill advertises and instructs use of capabilities including environment-variable access, local file reads/writes, shell execution, and outbound network calls, but the metadata shown in SKILL.md does not declare permissions for those operations. That mismatch is a real security issue because users and enforcement systems cannot accurately assess or constrain what the skill can do, especially since it handles credentials, reads local content/config files, writes previews/temp files, and connects to WeChat and arbitrary image URLs.
