Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill declares no explicit permissions while clearly requiring environment access and extensive network access to a third-party API. This undermines informed consent and platform policy enforcement because a caller may not realize the skill can transmit queries, account identifiers, and authentication material off-platform.
