Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation and metadata indicate access to environment variables, local files, and networked APIs, but it does not declare corresponding permissions. This creates a transparency and governance gap: users or the hosting platform may not realize the skill can read tokens, persist data locally, and transmit content to a remote service. In a skill that handles note syncing and conversation export, undeclared capabilities materially increase the risk of unintended data exposure.
