Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill requires environment access and makes remote API calls, but does not explicitly declare permissions despite those capabilities being central to its operation. This can undermine least-privilege review and informed consent because users may not realize the skill reads an API key from the environment and transmits queries to an external service.
