Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly requires sensitive capabilities—environment access for API keys, local file reads/writes for config and results, and outbound network access to YouTube and AssemblyAI—but does not declare permissions. This creates a transparency and least-privilege problem: users or hosting platforms cannot accurately assess or constrain what the skill can access, increasing the chance of unintended data exposure or overbroad execution.
