Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs users to set and use an API key via environment variables and includes executable code snippets that read from the environment, but no explicit permission declaration accompanies those capabilities. In agent ecosystems, undeclared secret access weakens transparency and can cause a host to grant broader capabilities than users expect, especially in a skill that also handles inbound untrusted email and outbound messaging.
