Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation declares no explicit permissions even though its described behavior clearly requires reading local files, accessing environment/configured credentials, and making network requests to Feishu. This creates a transparency and consent gap: users and policy engines may underestimate what the skill can access and transmit, increasing the risk of unintended data exposure.
