Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly documents network access and instructs reading and writing user workspace files such as portfolio, config, history, and memory files, but the finding indicates these capabilities are not formally declared as permissions. That mismatch is dangerous because users and the platform may not get accurate consent and visibility into what the skill can access or modify, especially given the financial and personal portfolio data involved.
