Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill requires capabilities to read/write local configuration, access environment variables, and make network requests, but it does not declare these permissions to users. That undermines informed consent and makes sensitive actions like credential persistence and outbound transmission harder to audit.
