Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation describes behavior that reads a local configuration file and sends data over the network, but it does not declare those capabilities as permissions. That mismatch reduces transparency and prevents proper policy enforcement or informed consent, especially because the webhook URL is a secret-bearing endpoint and memo content is transmitted externally.
