Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises and documents Python scripts that read local files, write sidecar artifacts, and interact with an external service, but the manifest does not declare corresponding permissions or otherwise surface those capabilities explicitly. This creates a transparency and policy-enforcement gap: users and host systems may underestimate the skill's access to local data and network endpoints, increasing the risk of unintended file disclosure or credential-related misuse.
