Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises no declared permissions while its documented and detected behavior requires network access and likely environment-based secrets for external APIs. This is dangerous because it obscures the true trust boundary: users and reviewers cannot accurately assess that the skill can fetch remote content, call third-party services, and use credentials, increasing the chance of unnoticed data exfiltration or unsafe deployment.
