Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill invokes Node scripts that necessarily access environment variables and remote services, but the manifest does not declare corresponding permissions or clearly surface those capabilities as security-relevant behavior. This creates a transparency and consent problem: users may enable a skill that can transmit prompt-derived memory to an external service and read sensitive environment-backed credentials without an explicit permission boundary.
