Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation advertises executable commands that read local reference data and make outbound requests to SEC endpoints, but it declares no permissions for file access or network use. This creates a capability/permission mismatch that can bypass user or platform expectations about what the skill is allowed to do, making review and policy enforcement weaker. The context makes this more significant because the skill is explicitly designed for external data retrieval and local issuer-reference access, so those capabilities are central rather than incidental.
