Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill exercises sensitive capabilities—environment variable access, file read/write, and outbound network calls—but does not declare permissions or present that capability surface explicitly. This increases the chance that agents or users invoke it without understanding it will read credentials, upload audio to a third-party service, and persist outputs locally.
