Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation describes capabilities to read environment configuration, write an API key via `set_api_key()`, and call external network services, but it declares no permissions or trust boundaries. This is dangerous because users and orchestrators cannot accurately assess that the skill will persist secrets locally and transmit data to a remote service, increasing the risk of unintended secret exposure or policy bypass.
