Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill describes file read/write and network behavior but does not declare corresponding permissions. That creates a transparency and consent gap: users or the platform may invoke a skill that can modify local state and contact an external site without explicit capability disclosure. In this context, the behavior is aligned with the stock-watcher purpose, so the issue is not hidden malicious functionality, but it is still a real security and governance problem.
