Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation describes code that performs network access and reads local files (for example, the city code table) but does not declare corresponding permissions. This creates a trust and review gap: the runtime capabilities of the skill exceed what a user or platform reviewer can infer from metadata, increasing the chance of unintended data access or undisclosed external communication.
