Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation indicates capabilities to read local files, write output files, and send medical record content to an external network API, but it does not declare any permissions. This creates a transparency and governance gap: operators may approve or run the skill without understanding that sensitive clinical text can be exfiltrated to a remote service and written to disk, increasing privacy and compliance risk.
