Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises and documents file I/O and outbound network behavior, but the metadata shown does not declare corresponding permissions. This can mislead users and hosting systems about the skill's actual capabilities, weakening informed consent and policy enforcement for a tool that reads input files, writes output files, and sends data to external services.
