Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares no permissions, yet its documented behavior includes environment variable access, local file read/write, and network calls. In a medical-record processing context, these capabilities materially increase the risk of unintended PHI exposure, policy bypass, and unsafe execution because operators may trust the skill as lower-privilege than it actually is.
