Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation directs the agent to read configuration state, write an API key via `set_api_key()`, and call remote services, yet no explicit permissions or user-facing capability disclosure is declared. This is dangerous because the skill gains effective access to environment/configuration, local file persistence, and network operations without transparent scoping, increasing the chance of silent credential handling or unintended side effects.
