Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill performs file reads of local login tokens and makes authenticated network requests, yet it declares no permissions. This creates a transparency and governance gap: the agent may access local credentials and external services without users or the platform being clearly informed, which is risky in a skill that handles account-authenticated data.
