Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill performs network access and local file writes/reads but does not declare any permissions, which undermines user/admin visibility into what the skill can do. In this context, the behavior is expected for fetching and exporting articles, but the lack of explicit permission declaration still creates a real security and governance gap because the skill downloads remote content and saves files to the user's Desktop.
