Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares itself as a local pre-scan utility, but its documented behavior requires reading a user-supplied SKILL.md, accessing API-key environment variables, and sending the full file contents over the network to a third-party LLM endpoint. Even though this is disclosed later in the document, the absence of explicit declared permissions creates a transparency gap that can mislead users about the actual trust boundary and data exposure involved.
