Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation indicates capabilities that involve environment variables and network access, and even references host configuration and API interaction, but it does not declare permissions. This creates a transparency and policy-enforcement gap: users or orchestration systems may approve or run the skill without understanding that it can access external services and local configuration, increasing the risk of unintended data exposure or unauthorized network use.
