Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill describes capabilities that perform outbound network access to a public API and local file writes for caching, yet no explicit permissions are declared. This creates a trust and policy gap: reviewers and runtime controls may not realize the skill can contact external services and write to disk, which can enable unintended data exposure, persistence, or policy bypass if the surrounding platform relies on declared permissions.
