Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs use of a CLI that stores credentials, reads and writes local state, and calls the Naver Search API, yet the skill metadata shown here declares no permissions. That mismatch is a real security issue because operators and policy systems cannot accurately assess or gate file and network access, increasing the chance of over-privileged or unexpected execution.
