Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly uses sensitive capabilities—environment-variable access for API keys, local file reads for config files, and outbound network access to a third-party service—yet it does not declare corresponding permissions in a machine-readable way beyond custom metadata. This creates a transparency and governance gap: users or hosting systems may not realize the skill can read credentials and transmit user-supplied data externally.
