Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly instructs the agent to perform network access and local file writes via Python scripts, but the manifest does not declare corresponding permissions or provide explicit user-facing consent boundaries. This creates a transparency and control gap: a user or platform may invoke a skill that can fetch remote content and write artifacts locally without the expected permission metadata.
