Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares no explicit permissions while its metadata and described operation require environment access, file reads, and outbound network use. That mismatch weakens user consent and platform enforcement, especially because it processes local session logs and sends derived content to third-party LLM providers.
