Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares no permissions, yet the documentation explicitly describes reading input files, optionally writing output files, and making network calls to an external/internal model endpoint using an appkey. This creates a capability/permission mismatch that can mislead reviewers and operators about the skill’s actual access needs, especially given it handles sensitive health data and transmits report contents off-host.
