Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill documentation describes capabilities to read subtitle files, write translated output, access environment variables for API credentials, and make outbound network requests, but no declared permissions are present. This creates a real security governance gap because users and platforms cannot accurately assess or constrain what the skill can access before use.
