Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly documents capabilities to read and write local files and access the network, but it does not declare permissions or equivalent user-facing constraints. That creates a transparency and policy gap: a caller may invoke a skill that can persist watch rules, modify cache/reference files, and fetch remote data without an explicit permission boundary or informed consent model.
