Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation describes capabilities to read local files, write output files, and send medical record text to an external MaaS endpoint, but it does not declare permissions or present explicit capability boundaries. In a medical-record processing context, undeclared file and network access is dangerous because it can lead to unreviewed exfiltration of sensitive health data and unexpected persistence of processed content.
