Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares required environment variables and documents Python execution, database connectivity, and local file access patterns, but it does not declare corresponding permissions or clearly constrain those capabilities. This creates a transparency and governance gap: operators may enable a skill that can access networked database resources and local files without explicit permission review.
