Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation clearly indicates capabilities to access the network and write output files, but the metadata shown does not declare permissions or prominently disclose those capabilities. This creates a trust and review gap: users or automation may invoke the skill without realizing it can contact external services and create local artifacts, which can lead to unintended data egress or file-system side effects.
