Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation describes capabilities including reading local machine identifiers, storing configuration files, making network requests to a Plex server, and executing via shell/cron, yet no explicit permissions are declared. This creates a transparency and governance gap: users and platforms cannot accurately review or constrain what the skill can access before installation or execution.
