Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly performs sensitive operations—reading environment variables, reading and writing local files, making network requests, and invoking CLI/runtime components—yet the metadata does not declare equivalent permissions in a machine-readable way. This creates a transparency and consent gap: a user or hosting platform may not be able to reliably enforce or review the skill's capabilities before execution, especially since the skill also handles plaintext credentials and uploads local files to a third-party service.
