Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly instructs the agent to use environment variables, read and write local files, and make network requests, yet the manifest declares no permissions. That creates a transparency and policy-enforcement gap: a host may auto-load or authorize the skill without understanding that it can access secrets, persist data, and exfiltrate content to a remote API.
