Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation indicates capabilities to read environment variables, write files, and perform network operations, but it does not declare permissions explicitly. This is a real security weakness because users and platforms cannot accurately assess or constrain what the skill may access, especially since it handles API keys, downloads remote content, and writes data into the workspace.
