Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly relies on environment access, file reads, and outbound network use, yet no permissions are declared. That mismatch weakens reviewability and consent boundaries, because an agent or platform may execute capabilities the user or host did not explicitly approve. In this context the actions are aligned with the skill’s purpose, so the issue is not covert exfiltration, but it is still a real least-privilege and transparency problem.
