Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares an API key in env and clearly relies on outbound network access, yet no explicit permissions are declared. That creates a transparency and governance gap: a user or platform may authorize the skill without understanding it can read secrets and transmit data externally. In a search/crawl skill, hidden env+network capability increases risk because user queries, URLs, and possibly extracted content may be sent to a third-party service.
