Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill declares required environment variables and demonstrates extensive outbound network access, but the file does not declare explicit permissions for those capabilities. This creates a governance and consent gap: a host system or reviewer may underestimate what the skill can access and transmit, including API-backed requests made with sensitive credentials.
