Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares no permissions, yet the analyzed behavior indicates access to environment variables, filesystem read/write, and network resources. That mismatch is dangerous because reviewers and users may trust the manifest boundary while the skill can actually fetch external data, persist local state, and potentially access sensitive runtime context without explicit disclosure.
