Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill appears to rely on environment variables and local file access but does not declare any explicit tool scope or permissions boundary. In a skill that handles sensitive health data, undeclared file/env capabilities increase the risk of over-broad access, accidental data exposure, and make it harder for the agent platform to enforce least privilege.
