Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill advertises functionality that implies environment access and local networking, but the manifest shown does not declare permissions or clearly warn users about those capabilities. Undeclared capabilities reduce transparency and can lead users to install a skill that opens a local server or reads environment/config context without informed consent.
