Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises operational behavior that clearly requires filesystem, network, shell, and likely email-automation capabilities, but it does not declare permissions. This weakens user consent and platform enforcement because a user cannot accurately assess what resources the skill will access before use.
