Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documents access to environment variables and networked services such as Circle and Moltbook, but the manifest section does not declare corresponding permissions. This creates a transparency and trust problem: an agent or user may install the skill without understanding that it will read secrets from the environment and contact external APIs, increasing the chance of unintended secret exposure or unauthorized outbound requests.
