Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill clearly depends on environment secrets and outbound network access to Apify and Contextual, but it declares no permissions to reflect those capabilities. This creates a transparency and policy-enforcement gap: an operator may approve or run the skill without realizing it can access credentials and transmit data externally, which increases the risk of unintended secret exposure or unauthorized external calls.
