Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 98% confidence
- Finding
- The skill requires network access and reads a sensitive environment variable, but it does not declare corresponding permissions in metadata. This creates a transparency and policy-enforcement gap: installers and sandboxing systems may not be able to accurately assess or restrict what the skill can do before execution.
