Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly requires environment variables, shell tools, local file input/output, and outbound network access, but it does not declare permissions accordingly. This undermines transparency and security review because users and platforms may not realize the skill can read local documents, send them to an external OCR API, and write results to disk.
