Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill advertises environment-variable based configuration and local persistence controls, but no explicit permissions are declared. That creates a transparency and consent problem: users may install a seemingly simple orchestration skill without realizing it can read configuration from the environment and alter behavior accordingly. In this context, the risk is elevated because the skill also handles conversation-derived insights and persistence settings, so undeclared env access can affect privacy-sensitive data handling.
