Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documents capabilities to write files under /tmp, make outbound network requests, and invoke shell commands, but does not declare corresponding permissions. This creates a transparency and governance gap: users and the host agent may authorize a seemingly simple PDF-to-note workflow without understanding that it performs broader local and remote operations.
