Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 98% confidence
- Finding
- The skill explicitly requires an environment secret (CLAW0X_API_KEY) and repeatedly sends repository URLs, code, and skill metadata to a remote API, yet the frontmatter declares only env requirements and no corresponding allowed tools or network permissions. This creates a permission-transparency failure: users may believe the skill performs local scanning while it actually depends on outbound network access and secret use.
