Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation advertises operational capabilities to read input files, write output files, and make network calls to an external model endpoint, but no corresponding permissions are declared. This creates a transparency and policy-enforcement gap: users or hosting platforms may not realize the skill exfiltrates sensitive health data over the network and persists results to disk, which is especially risky given the medical context and use of an appkey.
