Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill uses environment secrets and networked actions but does not declare permissions or warn users about those capabilities. In an agent context, hidden access to API keys and outbound email/network operations reduces transparency and can enable unintended external actions or misuse of credentials.
