Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly describes capabilities that require environment variable access, local file handling, and outbound network access, but it does not declare permissions for those operations. This creates a transparency and governance gap: users or orchestration systems may approve or run the skill without understanding that it sends data to external services and writes temporary files locally.
