Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares no permissions even though the documentation clearly indicates use of environment variables and outbound network access. This weakens user awareness and policy enforcement, making it easier for the skill to access secrets and transmit data without explicit consent boundaries.
