Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill declares access to secrets, file writes, and networked automation in metadata and documentation, but the finding indicates those capabilities are not explicitly declared as permissions. That mismatch is dangerous because users and the platform may not receive an accurate trust boundary: the skill can scrape external services, write local config/log files, and use API keys to modify Hunter campaigns, including adding leads that trigger outbound email workflows.
