Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation describes code behavior that reads local files/stdin, writes output files, and sends prompts and potentially document contents to a remote model API, but it declares no corresponding permissions. This creates a real security issue because integrators or users may invoke the skill without realizing it can exfiltrate sensitive medical content over the network and persist data to disk, especially given support for clinical summaries and record generation.
