Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation indicates use of both network access and an environment variable (`CLARITY_API_KEY`), but the skill does not declare corresponding permissions. Undeclared capabilities reduce transparency and can lead to users or hosting platforms granting trust without realizing the skill can exfiltrate environment data or make outbound requests, even if the described use case appears legitimate.
