Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill documentation describes a script that can read local files, write output files, and make network requests to an external medical-model API, yet it declares no permissions. This creates a transparency and governance gap: deployers may underestimate the skill's access to sensitive medical data and allow it to process protected records without explicit review or sandboxing.
