Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation directs the agent to call multiple external HTTP endpoints and read a local token file, but there is no declared permission model or user-facing disclosure of those capabilities. This creates hidden network/data-access behavior, making it easier for the skill to transmit sensitive data unexpectedly and harder for the platform to enforce least privilege.
