Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill explicitly relies on network access, local file input, and likely environment access via its Python script, but the skill file does not declare permissions. That creates a governance gap: users and the platform cannot easily review or constrain what the skill is allowed to access, increasing the chance of unintended data exposure or overbroad execution.
