Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill declares executable capabilities and data access patterns in its documentation and metadata (`aws`, `curl`, `python3`, environment-variable configuration, and writes to local files), but it does not declare explicit permissions for those operations. This creates a trust and review gap: consumers may authorize or run the skill without realizing it can read sensitive environment configuration, invoke shell commands against AWS, and write potentially sensitive health/log data to disk.
