Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation describes file I/O, SQLite persistence, and price updates via `requests`, but it does not declare corresponding permissions. This creates a transparency and consent problem: users or orchestrators may run the skill without realizing it can read/write local files and make outbound network requests, increasing the chance of unintended data exposure or destructive actions such as database reset.
