Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill advertises no explicit permissions while its documented behavior implies environment access, local file read/write, and network communication. This is dangerous because users and platforms cannot accurately assess the real trust boundary, especially when the skill also stores credentials and calls an external service.
