Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill describes file reads from `~/yahoo/` and outbound network access to Yahoo Finance, but it does not declare explicit permissions for those capabilities. Undeclared capabilities weaken user consent and platform enforcement because the skill can access local data and make external requests without a clear permission contract. In this context the behavior is somewhat bounded by the documentation, but the absence of formal permission declarations still creates a real transparency and policy gap.
