Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation indicates capabilities to read environment variables, invoke shell commands, and access the network, but it does not declare permissions explicitly. This creates a transparency and governance gap: users and hosting platforms may not understand that API keys will be read from the environment and sent to an external service, increasing the risk of over-privileged execution or accidental secret exposure. In this context, network and env access are expected for a video-generation skill, which lowers suspicion of maliciousness, but the lack of declared permissions is still a real security issue.
