Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill documentation instructs the agent to access environment configuration, persist an API key via local file/config writes, and call external network APIs, yet no permissions are declared. This creates a trust and governance gap: a host may expose capabilities the user did not explicitly approve, and the skill can solicit and store sensitive credentials without a clear permission model.
