Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill metadata declares required binaries and an API key environment variable, and the skill documentation clearly instructs users to make outbound requests to a third-party API, yet no explicit permissions model is declared. In an agent setting, undeclared access to environment variables and network capabilities weakens transparency and informed consent, making it easier for a host or user to underestimate what the skill can access and where data may be sent.
