Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill appears to use environment access, local file read/write, and network capabilities while declaring no permissions, which breaks transparency and prevents informed consent or policy enforcement. In this context, the omission is more dangerous because the skill also instructs collecting and persisting an API key, so undeclared file and env access could be used to store or expose credentials unexpectedly.
