Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation indicates use of environment variables, network access to Azure OpenAI, and file writes for saving images and HTML output, but no permissions are declared. This creates a transparency and governance gap: users or hosting platforms may authorize or run the skill without understanding that it can access secrets, make outbound requests, and write files locally.
