Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill metadata declares runtime requirements and the documentation clearly indicates use of environment variables, outbound API calls, and writing generated MP3 files, yet no explicit permissions are declared. This creates a transparency and governance gap: users or orchestrators may invoke a skill with network and file-write behavior without clear permission signaling, increasing the risk of unintended data disclosure or policy bypass.
