Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly instructs use of local files, output writing, possible environment-backed Bearer authentication, and outbound network access to PatSnap/MCP services, yet the metadata shown does not declare corresponding permissions. That mismatch is dangerous because it defeats least-privilege review and can cause a host agent to grant or exercise broader capabilities than users or platform policy expect, especially given the skill handles confidential IP documents and API credentials.
