Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill documentation describes capabilities that imply network access, reading configuration files, and writing screenshots/reports, but it declares no permissions. That creates a trust and review gap: operators may approve or run the skill without understanding that it can access Grafana endpoints and handle sensitive local files such as API-key-bearing configs. In a Grafana inspection context, this is more dangerous because the workflow explicitly involves authenticated access to monitoring infrastructure and local artifact generation.
