Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation indicates use of environment variables (`SIMMER_API_KEY`) and outbound network access to public APIs, yet no permissions are declared. This creates a trust and sandboxing gap: a platform or reviewer may underestimate the skill's access needs, and if executed in an agent framework, the skill could read secrets from the environment and communicate externally without explicit user awareness.
