Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 78% confidence
- Finding
- The skill metadata declares required binaries and environment variables, and the documented workflow invokes a Python script that calls an external API using an API key, but there is no explicit permission declaration for network or secret/environment access. This creates a governance gap: the runtime can access sensitive capabilities that are not transparently disclosed, making review and policy enforcement harder.
