Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation instructs use of scripts that read local image files, persist API credentials locally, and make outbound network requests, yet the skill declares no permissions. This creates a transparency and governance gap: users and host platforms cannot accurately assess or constrain the skill's actual capabilities, increasing the risk of unintended file access, secret storage, or network exfiltration.
