Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill requires access to environment variables and makes outbound network requests, yet does not declare those capabilities explicitly. This can mislead reviewers and users about what the skill can access, reducing transparency and weakening permission-based safety controls.
