Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation describes capabilities that include network access and local file read/write behavior, but it does not declare permissions or provide explicit permission boundaries. This is dangerous because agents or users may invoke the skill without understanding that it can access external sites and modify local files, increasing the chance of unintended data exposure or filesystem changes.
