Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill requires an environment variable API key and makes outbound network calls, but it does not declare permissions for those capabilities. This weakens transparency and reviewability because users and hosting platforms may not realize the skill can access secrets and transmit data externally, increasing the risk of unintended credential exposure or unreviewed data egress.
