Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation instructs the agent to read environment state, prompt for an API key, persist it locally, and call remote services, but it declares no permissions for env, file read/write, or network use. This creates a transparency and consent problem: users and policy layers cannot accurately assess what the skill can access or modify, especially because it handles secrets and performs outbound requests.
