Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises network-capable behavior via API/environment-based analysis but does not declare permissions or boundaries for that access. In an agent setting, this can lead to unexpected outbound requests or access to sensitive billing data using ambient API keys, which is a security and privacy risk even if the feature is intended.
