Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares no permissions, yet its documented behavior requires environment access, local file read/write, and outbound network calls. This is dangerous because it hides the true trust boundary from users and reviewers, especially when the skill also stores API credentials and sends data to an external service.
