Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation describes functionality that reads local files and performs outbound network requests, but it does not declare any permissions for those capabilities. Missing permission declarations can cause the agent platform or users to underestimate what the skill can access, reducing transparency and weakening review and consent controls. In this case the behavior is aligned with the stated purpose of scanning files and URLs, so the issue appears to be an undeclared-capability problem rather than overtly malicious behavior.
