Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documents capabilities that rely on environment-variable access and outbound network access to Google APIs, but it does not declare permissions accordingly. This can cause users or an execution framework to underestimate the skill's reach, especially since it also handles sensitive credential material via environment variables and local key files.
