Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill advertises execution via a Python script that reads input files, writes output files, and sends data to a remote API, but the manifest does not declare any permissions or clearly expose those capabilities to reviewers/users. This creates a transparency and governance gap: sensitive clinical questions and literature excerpts may be processed and transmitted off-box without an explicit permission model, increasing the risk of unauthorized data handling.
