Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises capabilities that include environment access, local file read/write, and network access, but does not declare permissions or clearly communicate those capabilities to the user. In this context, that is dangerous because the skill handles local file paths, persists API keys to a local .env file, and sends data to a remote service, creating hidden trust and consent boundaries.
