Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill uses environment variables and outbound network access but does not declare corresponding permissions in its metadata, which weakens security transparency and informed consent for installers. In a skill ecosystem, undeclared capabilities can lead users to run code that accesses secrets and external services without clear upfront disclosure.
