Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation clearly directs use of environment variables, local file I/O, and outbound network access, yet it declares no permissions or capability boundaries. This is dangerous because users and host platforms cannot accurately assess or constrain what the skill will access, increasing the chance of overprivileged execution and unnoticed data flow to external services.
