Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation clearly indicates capabilities to read files, write outputs and voice-profile data, and contact a local HTTP API, yet the skill metadata declares no permissions. This creates a transparency and consent problem: users and policy enforcement layers cannot accurately assess or gate the skill's access before use.
