Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 78% confidence
- Finding
- The skill advertises only tutoring functionality, but the metadata and documented workflows imply access to environment variables, network communication, and local file operations without declaring permissions or clearly warning the operator. This creates a transparency and least-privilege problem: users may authorize a seemingly harmless tutor skill that can also persist data locally and communicate with remote services using sensitive credentials.
