Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly relies on environment access and browser/network-capable tooling (`agent-browser`, local scripts, file output), but the manifest does not declare permissions. Undeclared capabilities make security review and user consent weaker, and can hide the true operational scope of a skill that captures browser request data and writes reports locally.
