Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly requires an environment variable API key and documents extensive outbound HTTP requests, yet there is no clear declared permission model for environment access or network use. This weakens user and platform visibility into sensitive capabilities and can lead to silent use of credentials and remote data transmission.
