Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill advertises executable behavior that depends on environment-sensitive data but declares no permissions, which weakens user awareness and any permission-gating the platform may rely on. In context, the skill is a quota checker that appears to inspect local auth/session state, so undeclared env-related capabilities materially expand what it can access beyond what the metadata communicates.
