Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill clearly requires an API key and instructs use of a Python script that performs outbound network requests, yet it does not declare corresponding permissions. This creates a transparency and governance gap: reviewers and users cannot accurately see that the skill accesses environment secrets and external services, which can lead to unintended secret use or unreviewed network exfiltration paths.
