Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares no explicit permissions while requiring an API key and making networked requests, which hides its effective capability surface from reviewers and policy controls. This is dangerous because under-declared permissions reduce transparency and can allow a seemingly simple content-extraction skill to access secrets and external services without clear operator awareness.
