Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill advertises no explicit permissions, yet its documented behavior clearly relies on environment variables and outbound network access. That gap is dangerous because downstream users or orchestrators may treat the skill as low-risk/read-only while it can still transmit data externally and consume credentials implicitly.
