Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation advertises capabilities that read local files and stdin, write output files, and send prompts to a remote medical-model API, but it declares no corresponding permissions. This creates a trust and policy gap: operators may deploy the skill without realizing it can exfiltrate sensitive medical questions or patient-related content over the network and persist data to disk.
