Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation advertises capabilities that require network access and likely environment/config access, but it does not declare permissions or clearly scope those privileges. Undeclared capabilities are dangerous because reviewers and users cannot accurately assess what data the skill can access or where voice data, transcripts, or API credentials may be sent.
