Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation instructs the agent to read and write files under the user's home directory and to fetch stock data over the network, but the skill declares no permissions. This creates a transparency and policy-enforcement gap: users and the platform cannot accurately assess or constrain what the skill will access, which is especially relevant because it stores persistent state and reaches external data sources.
