Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill metadata declares required binaries and an API key, and the documentation shows network access plus report output to files, but no explicit permission declaration is present. This creates a transparency and policy-enforcement gap: users may invoke a skill that can exfiltrate data to external services or write files without those capabilities being clearly declared and consented to.
