Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill metadata declares only an environment requirement, but the documentation explicitly states the implementation reads a local configuration file and calls external AMap APIs. This mismatch weakens permission transparency and can lead users or platforms to grant or review the skill under incomplete assumptions about file access and network behavior.
