Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill uses both environment variables and network access to authenticate to a WebUntis instance, but the skill metadata does not declare these capabilities as permissions. This creates a transparency and governance gap: operators may enable or run the skill without realizing it can read secrets from the environment and make outbound authenticated requests, which can lead to unintended credential use or data exposure.
