Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly performs sensitive operations—reading mail via IMAP, sending mail via SMTP, writing config/secrets/state files, invoking pip/shell commands, and fetching remote links—yet no explicit permissions are declared. This creates a transparency and consent gap: users or orchestrators may invoke a skill with credential, filesystem, network, and package-install capabilities without an appropriate permission boundary or review signal.
