Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill describes capabilities that access environment secrets, read/write local files, and send data over the network, but it does not declare corresponding permissions. That mismatch weakens user and platform transparency, making it easier for a skill handling sensitive meeting recordings and transcripts to access secrets or persist data without clear consent boundaries.
