Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation indicates it uses environment variables for API keys and makes outbound network requests, but it does not declare corresponding permissions. Undeclared env and network capabilities reduce transparency and can bypass user or platform expectations about what the skill can access, especially since API-bearing environment variables are involved.
