Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill uses environment access, network access, and file writing, but does not declare permissions or otherwise make those capabilities explicit. This creates a transparency and policy-enforcement gap: a host may invoke the skill without realizing it can read secrets like API keys, contact external services, and write files, increasing the chance of unintended data exposure or unauthorized side effects.
