Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares no permissions while its documented behavior clearly performs network access to Uniqlo's API and writes Markdown files to disk. This mismatch can bypass user and platform expectations, reducing transparency and making unauthorized file creation or external data access more likely when the skill is invoked.
