Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill declares required binaries and environment variables and clearly performs outbound network requests, but it does not declare corresponding permissions. That mismatch can prevent users and harnesses from accurately understanding the skill's capabilities, leading to unintended secret access and external data transmission.
