Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill declares no permissions even though its documented behavior requires reading Odoo credentials from environment variables and making outbound network requests to both Odoo and an external search engine. This creates a transparency and governance gap: users and reviewers cannot accurately assess what sensitive capabilities the skill will exercise, increasing the chance of unintended credential use or external data exposure.
