Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation indicates use of network access to clarityprotocol.io and reads the optional CLARITY_API_KEY environment variable, but the finding says no permissions are explicitly declared. Undeclared network and environment access weakens the security boundary because a host may allow the skill to run without clearly informing reviewers or users that it can exfiltrate environment-derived secrets or make outbound requests.
