Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation indicates capabilities to access external market data and generate output files, yet it declares no permissions. This creates a transparency and policy-enforcement gap: a host system or user may approve the skill expecting a passive analysis tool, while it can still perform network access and write artifacts such as PNG, Markdown, and JSON outputs. In this context, the behavior appears aligned with the stated stock-analysis workflow, so the issue is more about undeclared capability exposure than clearly malicious abuse.
