Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill describes file read/write and likely script execution capabilities but does not declare permissions, creating a transparency and governance gap. Even though the stated behavior is local-only, this skill handles sensitive insurance and claims data, so undeclared capabilities can lead to unexpected access to local files or environment data and make review, sandboxing, and user consent weaker.
