Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises capabilities to read installed skills, schedule scans, and send reports to external channels, which implies file access, network use, and potentially shell/process execution, yet no permissions are declared. This mismatch is dangerous because users and the platform cannot accurately understand or constrain what the skill can access, and the automatic exfiltration of scan results to all configured channels increases the risk of sensitive data disclosure.
