Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill declares required binaries and sensitive environment variables and clearly instructs users to run Python commands that will access external services, but it does not declare corresponding permissions/capabilities in a transparent way. This can mislead users and reviewers about the skill's actual access to environment secrets, local files, and network resources, increasing the risk of unintended mailbox access or outbound communications.
