Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares no permissions even though its documented behavior clearly includes reading local files, writing report output, and optionally sending content to an external API. This is dangerous because users and the hosting agent cannot make an informed trust decision about filesystem and network access, especially given the skill processes potentially sensitive client livestream data.
