Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill describes executable capabilities that include network access, file read/write, and environment usage, but it does not declare permissions or constraints. That mismatch is dangerous because an agent may perform sensitive actions such as persisting session tokens locally and sending authenticated requests to external APIs without an explicit permission boundary or user awareness.
