Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation indicates use of environment secrets and outbound network access, but it does not declare permissions or provide a clear trust boundary for those capabilities. This can lead to unexpected credential use and external data transmission during execution, reducing visibility and making misuse harder to audit.
