Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation describes capabilities that use network access and environment-controlled paths, but it does not declare corresponding permissions. This creates a transparency and policy-enforcement gap: an agent or reviewer may authorize the skill under incomplete assumptions while it still performs external fetches and reads behavior from environment variables.
