Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises and demonstrates network access and file output, but the metadata declares no permissions. That creates a transparency and governance gap: an agent or reviewer may approve or invoke the skill without understanding that it can fetch arbitrary URLs and write scraped data to disk, including potentially sensitive content.
