Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares access to an API key and invokes a Python script that will likely make outbound network requests, but it does not explicitly declare permissions for environment-variable and network use. This creates a transparency and governance gap: hosts or users may invoke the skill without understanding that secrets are read from the environment and sent to an external service, increasing the risk of unintended secret exposure or unreviewed external data egress.
