Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises executable usage that reads local files, writes output files, and sends sensitive health-record content over the network to an external API, yet it declares no explicit permissions or trust boundaries. In a healthcare context, this omission is dangerous because operators may not realize the skill has data-access and exfiltration capability, increasing the risk of unauthorized PHI handling and policy bypass.
