Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documentation declares no permissions even though it requires environment-based secrets and external service access. This can mislead users and platforms about the skill's actual capabilities, reducing informed consent and making accidental overexposure of credentials or unreviewed networked behavior more likely.
