Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill explicitly instructs the agent to read an API key from the environment and make outbound HTTP requests, but it does not declare corresponding permissions. This creates a capability/permission mismatch that can bypass user or platform expectations about secret access and network use, increasing the risk of unintended data exfiltration or unauthorized external calls if the skill is invoked in a broader agent context.
