Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill performs network access and reads environment variables but does not declare those capabilities. That hides the true privilege and data-access surface from reviewers and users, making it easier for the skill to transmit identifiers or secrets unexpectedly. In this file, the undeclared capabilities are directly used for billing calls and user identification.
