Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation describes executable behavior that reads local files, optionally writes output files, and makes outbound network requests, yet it declares no permissions. This is a real security issue because operators and policy engines cannot accurately understand or constrain what the skill can access, and the skill processes potentially sensitive medical data that could be sent to a remote API.
