Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 79% confidence
- Finding
- The skill clearly describes capabilities that require network access to a Moodle instance and access to a local secrets file, yet it does not declare permissions or scope those capabilities. That creates a transparency and control problem: operators and users cannot reliably understand what the skill may do or restrict it appropriately, increasing the risk of unintended writes to Moodle data or secret handling mistakes.
