Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation declares no permissions, yet the described functionality and static analysis indicate network access and local file writes. This creates a transparency and consent problem: users or hosting platforms may grant execution assuming a lower-risk capability set than the skill actually uses.
