Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises and documents capabilities that entail reading local files, writing outputs such as HTML/cache/config files, using environment/configured secrets, and making network requests, but the manifest does not explicitly declare a corresponding permission model. This creates a transparency and containment gap: an agent or user may approve the skill under a narrower trust assumption than the skill actually requires.
