Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly requires environment variables and performs outbound network access, but the skill metadata does not declare explicit permissions for those capabilities. This weakens transparency and permission enforcement, making it easier for a user or host system to run a networked skill without clear security review of its access to secrets and external services.
