Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation describes use of an environment variable API key and outbound requests to ZenMux, but it does not declare permissions corresponding to those capabilities. This creates a transparency and governance gap: users and platforms cannot accurately assess that the skill accesses secrets and communicates with an external service before use.
