Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill declares required environment variables in metadata and instructs use of API keys, but the static finding indicates there is no explicit permission declaration corresponding to those capabilities. In a skill that persists transcripts to disk and sends summaries to external services, undeclared env/code capabilities reduce transparency and can cause the skill to be invoked with more access than users expect.
