Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documents use of an API key via environment variable and a networked CLI, but it does not declare any explicit tool scope such as allowed-tools or permissions. That omission weakens containment and reviewability: an agent invoking this skill may be granted broader environment and network access than the skill description makes explicit, increasing the risk of secret exposure or unintended outbound API actions.
