Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation instructs the agent to rely on SMTP credentials injected through environment variables, but the skill manifest does not declare any corresponding permission for env access. This creates a permission-model gap: the skill can consume sensitive runtime secrets without transparent declaration, making review and enforcement weaker and increasing the chance of unintended credential exposure or overprivileged execution.
