Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill advertises and demonstrates network access and local state persistence (`--store`, `--out`) but declares no permissions or capability boundaries. Missing permission disclosure is dangerous because it hides the real trust surface from the operator, making unintended file writes or external requests more likely to be approved and executed without informed consent.
