Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly requires file writes and network access to store Telegram sessions/configuration and communicate with Telegram, AI providers, and optional notification bots, yet no permissions are declared. This creates a governance gap: users and orchestrators are not given an accurate security boundary for a skill that handles highly sensitive credentials and private communications.
