Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill documentation describes behavior that uses environment variables, reads and writes local files, and performs network operations, but it declares no corresponding permissions. This creates a transparency and sandboxing problem: a caller or platform may authorize the skill under the false assumption that it is low-privilege, while it can access credentials, persist data locally, and contact external services.
