Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill advertises web automation, scraping, scheduling, and browser-driven actions that inherently imply network access and likely file output, yet it declares no explicit permissions or constraints. This mismatch weakens policy enforcement and review because consumers and hosting systems cannot reliably determine what capabilities the skill will exercise.
