Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill uses network access and environment variables but does not declare those capabilities or permissions. This reduces transparency for reviewers and users, and in this case hides the fact that the skill can both contact external services and read billing-related environment state before performing its advertised task.
