Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly documents reading local files (images, config) and making network requests to a remote API, yet it declares no permissions. That mismatch can prevent informed consent and weakens security review because users are not explicitly told the skill can access local data and transmit it externally.
