Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill requires environment secrets (`ALPHASHOP_ACCESS_KEY` and `ALPHASHOP_SECRET_KEY`) and performs outbound API access, but the manifest does not declare corresponding permissions. Undeclared access to secrets and network creates a transparency and policy-enforcement gap: a host may expose credentials or allow external requests without users/admins being clearly informed at install or review time.
