Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises only metadata and usage instructions, but the documented execution path clearly requires file reading, file writing, shell-accessed external tools, environment/appkey handling, and outbound network access. In a medical-records context, undeclared capabilities are dangerous because they expand the trust boundary without explicit user consent and enable sensitive health data exfiltration or unsafe document processing.
