Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises executable capabilities such as file read, file write, and network access, but does not declare any permissions or trust boundaries. This creates a transparency and governance gap: users or the host platform cannot accurately assess what the skill may access or transmit before use, increasing the risk of unauthorized data access or exfiltration.
