Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill advertises executable behavior that includes file reads/writes and references to external URLs, but it does not declare explicit permissions or constraints in a machine-enforceable way. Even though the prose claims 'local-only' and 'no network requests,' the mismatch between detected capabilities and undeclared permissions creates a trust gap and can lead to overbroad access when the skill is installed or reviewed.
