Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill describes capabilities to read environment variables, write files, and make network requests, but does not declare permissions or provide clear trust boundaries. In this context, the undocumented combination is risky because the workflow explicitly reads an API key, persists it to `.env`, and sends requests to a third-party service, which can surprise users and reviewers.
