Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill documentation describes capabilities to read local files, optionally write outputs/preprocessed text, and send medical record content to a remote API, yet it declares no explicit permissions. This creates a governance gap: operators may invoke the skill without clear visibility or policy enforcement around sensitive file and network access, which is especially risky because the processed content is medical data and the skill can persist derived text when flags are used.
