Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation describes capabilities that access environment variables, write files, use the network, and invoke shell-installed tooling, but it does not declare permissions or present those capabilities to the user in a structured way. This creates a transparency and consent problem: users may trigger downloads, local file writes, and external API transmission without clearly understanding the operational scope.
