Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation directs the model to use environment access, local file reads/writes, and network calls, but it declares no permissions or trust boundaries. This creates a transparency and security problem because users and hosting platforms cannot accurately assess that the skill will persist API secrets locally and communicate with remote services.
