Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares no permissions while clearly requiring network access and use of secret-bearing configuration fields (`apiKey`/`secretKey`). This mismatch undermines least-privilege review and can cause operators or higher-level tooling to invoke the skill without understanding that it transmits user-supplied product identifiers and credentials to an external service.
