Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation indicates it reads local files, invokes Python/scripts, and sends data to a remote API, yet it declares no explicit permissions. This creates a transparency and governance gap: users and platforms may not realize the skill can access local files, execute shell/Python commands, and transmit content externally.
