Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation instructs use of environment variables, network access, and local file writes/reads, but no explicit permission model or user-facing disclosure is declared. This creates a real security issue because the skill can access secrets and persist data locally while contacting an external API, reducing transparency and increasing the chance of overbroad execution in hosts that rely on declared permissions.
