Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill clearly requires environment access to read CERAMIC_API_KEY and network access to send queries to api.ceramic.ai, yet the skill text does not declare explicit permissions beyond metadata requirements. This mismatch weakens review and policy enforcement because an agent may invoke code-capable behavior without a clear permission contract, increasing the chance of unintended secret use or outbound requests.
