Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares use of environment variables and includes a search component that depends on an API key and external retrieval, but it does not expose corresponding permissions or a clear trust boundary. This can cause the host system to execute a skill with undeclared network and secret access expectations, reducing operator visibility and increasing the chance of unintended data egress or policy bypass.
