Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill instructs the agent to perform network fetches and write files to a local workspace, but those operational capabilities are not explicitly declared as permissions. That creates a transparency and governance gap: a user or platform may believe this is a read-only advisory skill when it can modify local state and access external resources.
