Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill invokes shell, reads environment variables, accesses local files, writes persistent auth/coupon data, and calls remote services, yet the manifest does not explicitly declare these capabilities. This creates a transparency and consent gap: a host agent or reviewer may treat the skill as lower-risk than it really is, while the skill handles tokens, device identifiers, phone-related data, and network operations.
