Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill clearly requires network access and handling of environment/local credential material, yet no explicit permissions are declared. That creates a transparency and policy-enforcement gap: users or hosting frameworks may invoke a networked OAuth flow and credential storage behavior they were not clearly warned about. In this context, the omission is more concerning because the skill deals with sensitive health data and tokens.
