Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documents capabilities to read local files (config and cookie files), write files/logs, and access the network, but does not declare permissions or prominently scope those actions. This is dangerous because an agent may be granted broader implicit access than a user realizes, especially when handling session cookies and external notification endpoints.
