Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill advertises and instructs use of multiple code-driven capabilities such as Node scripts, polling, OAuth credential retrieval, and likely environment-backed configuration, yet no permissions are declared. This creates a transparency and governance gap: users and policy enforcement layers cannot accurately understand that the skill may access runtime capabilities and external services.
