Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill documents file read/write and network-capable behavior but does not declare corresponding permissions, which weakens transparency and prevents effective policy enforcement by the platform or user. In this skill's context, that matters more because it polls email, persists state, and sends replies automatically, creating a remote command channel with filesystem and network side effects.
