Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill declares `primaryEnv: none` and no required environment permissions, yet the documentation clearly indicates use of environment-held API credentials, network access to external endpoints, and file output under `output/`. This mismatch is dangerous because it hides the skill's real capabilities from reviewers and operators, undermining least-privilege controls and informed consent about external data transmission and local artifact creation.
