Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation indicates code capabilities including network access and file reads, but no permissions are declared. This creates a transparency and governance gap: consumers may approve or run the skill without understanding that it can contact LM Studio endpoints, query models, and potentially read local files such as model catalogs or profiling data.
