Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares no explicit permissions, yet its documented behavior clearly includes reading local files, optionally writing output files, and sending patient-derived medical text to a remote API. This creates a transparency and governance gap: operators may approve or run the skill without realizing it performs network exfiltration of sensitive health data and filesystem access, increasing the risk of unauthorized data handling.
