Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises local file summarization and automatic webpage fetching, which imply file-read and network-access capabilities, but it does not declare any permissions or trust boundaries. This can mislead users and hosting platforms about what the skill may access, reducing transparency and increasing the risk of unintended local data exposure or outbound requests.
