Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill advertises significant capabilities including file processing, logging, model management, and downloads, yet declares no permissions. That mismatch reduces transparency and can cause the host or user to approve a skill without understanding that it may read/write local files and access the network, which is especially sensitive for a private-data processing tool.
