Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill invokes a bundled CLI and explicitly documents access to local config/database files, persistent writes under the user's home directory, and network-backed data retrieval, yet it declares no permissions. This creates a transparency and consent problem: a caller may treat the skill as low-risk while it can read/write local state and reach external sources, increasing the chance of unintended data exposure or side effects.
