Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documents and encourages use of network access, environment variables, file reads, and file writes, but declares no permissions. That mismatch hides the true capability surface from the platform and users, making credential access, outbound requests, and local log/config handling less auditable and easier to misuse.
