Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation describes capabilities that imply access to environment variables, local files, and attachment download paths, yet no explicit permissions are declared. In an agent environment, undeclared access to env, file read/write, or shell-like capabilities weakens transparency and can let a high-privilege skill handle sensitive data without clear user or platform review.
