Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation describes use of environment variables, local file read/write, network access, and shell execution, but no explicit permission declaration or user-facing capability disclosure is present. This creates a real governance and trust problem because the skill can download remote content, invoke local tools, and write artifacts without a clearly declared permission model.
