Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The manifest declares no permissions, yet the documentation clearly indicates local file access for credential persistence and network access for API calls. This creates a transparency and trust problem: users and platforms cannot accurately assess what sensitive operations the skill performs before use.
