Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises and operationalizes network, shell, file read, and file write behavior but does not declare permissions or provide any explicit trust boundary for those capabilities. In this context, the skill handles OAuth credentials, refresh tokens, and bulk export of sensitive health data, so missing permission disclosure can cause unsafe execution in environments where users or policy engines rely on declared permissions to assess risk.
