Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill declares no permissions while its documented behavior requires environment access, local file reads/writes, and network calls. This under-disclosure is dangerous because it prevents users and platforms from making an informed trust decision and hides the real data exposure surface, including credential handling and outbound transmission of email addresses.
