Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill advertises only symptom-recognition functionality, but its documented behavior and referenced scripts imply filesystem, shell, network, and environment access without any declared permission model or user-visible scoping. In a medical context, these undeclared capabilities increase the risk of unexpected data exfiltration, local persistence, or command execution beyond what a user would reasonably expect.
