Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill metadata declares required binaries and an environment variable, and the documented behavior clearly depends on making outbound requests to a third-party API, but there is no explicit permissions declaration covering network/environment access. This creates a transparency and governance gap: reviewers and users may not understand that data leaves the system and that a secret API key is consumed at runtime.
