Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises extensive file parsing, state persistence, and channel/API integration, but it does not declare permissions even though its documented behavior implies file read, file write, and network access. This is dangerous because users and the platform cannot accurately scope or gate the skill's capabilities, increasing the risk of overbroad access to sensitive business data and external systems.
