Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation describes capabilities that require environment variable access, local file writes, and network communication, yet no explicit permissions are declared. This creates a transparency and governance gap: operators may approve a seemingly simple read-only skill without understanding that it stores tokens locally, downloads attachments, and talks to external OAuth/Graph endpoints.
