Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation exposes capabilities to read environment data and read/write local files, but it does not declare any permissions or warn the user about those accesses. That creates a transparency and consent problem: an agent may invoke a seemingly simple CRM skill that can persist sensitive lead data and potentially access broader local context than the user expects.
