Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill explicitly describes downloading metadata and PDFs from many remote sources, allows user-configured custom sources, and lists dependencies consistent with network access and document processing, yet no permissions are declared. That mismatch is a real security issue because it hides material capabilities from users and reviewers, reducing informed consent and making it easier for network/file/shell-capable implementations to overreach beyond expected behavior.
