Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documents capabilities to read local files, write local records, and send network requests, but it does not declare corresponding permissions. That creates a transparency and consent failure: users and hosting systems cannot accurately evaluate what the skill will access before use. In this context the risk is heightened because the undocumented capabilities include reading local credential files and transmitting data to a remote endpoint.
