Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation describes capabilities requiring environment variable access, network access, and file writes/reads, but no explicit permissions are declared. This creates a trust and review gap: an agent may invoke a skill with broader capabilities than users or platform policy expect, increasing the risk of unintended data access or exfiltration. In this context, the skill performs external media queries and can write result files, so undeclared capabilities are materially relevant rather than theoretical.
