Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to read a local login token file and make outbound network requests, but it declares no corresponding permissions. Hidden or undeclared file-read and network capabilities weaken the trust boundary, because users and the platform cannot accurately assess what local data and external services the skill will access. In this context, the file access targets authentication material, which makes the omission more sensitive than a routine local read.
