Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill performs network access and file reads but does not declare corresponding permissions, creating a capability/permission mismatch. This is dangerous because users or hosting platforms may underestimate what the skill can do, especially since it handles a sensitive Discord webhook secret and a local ledger file.
