Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation clearly requires environment variables containing secrets and instructs use of a Python script that performs outbound API calls, yet no declared permissions are described. This creates a transparency and governance gap: users or platforms may not realize the skill accesses credentials and contacts remote services, which increases the chance of unsafe deployment and insufficient review.
