Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill describes capabilities to write local files, access external network services, and invoke shell tooling such as pandoc, but it does not declare any explicit permissions or safety boundaries. This creates an authorization and transparency gap: users and the platform cannot clearly evaluate or constrain sensitive operations like exfiltrating report contents, storing local history, or executing external commands.
