Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises handling sensitive vaccination and health-status inputs, and its documentation shows file read, file write, and network capabilities, but it declares no permissions or explicit disclosure of those capabilities in a machine-enforceable way. This creates a trust and governance gap: users or platforms may approve the skill without understanding that protected health-related data can be read from disk, transmitted to a remote API, and written to output files.
