Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation instructs use of environment variables plus reading and writing local files, but the manifest does not declare those capabilities. Hidden capability gaps matter because users and policy layers cannot accurately assess what the skill needs to access, especially when it handles PDFs and optional credentials. In this context the issue is transparency and control failure rather than direct code execution, but it increases risk when combined with OCR and external API usage.
