Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The manifest declares a Python tool (`alignment_checker.py`) and the content references reading OKR data plus automated analysis, which implies operational capabilities without an explicit permissions declaration. Undeclared file-read and possible network access create a trust gap: users and the host may invoke code that can access local data or external services without clear consent or policy review.
