Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises and demonstrates capabilities that require sensitive operations such as network access, environment-variable access, and likely file I/O, but it does not declare any permissions. This creates a transparency and trust problem: a user or platform may invoke the skill without realizing it can access secrets, call external APIs, or modify local state.
