Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill declares no permissions while the documented behavior clearly implies environment variable access, file reads, and possible network access for model downloads. This creates a transparency and trust gap: a caller may assume the skill is fully local and low-privilege, but invoking it can still touch local files, process environment configuration, and potentially contact external infrastructure.
