Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill metadata declares runtime requirements such as environment variables but does not clearly declare the effective capabilities implied by the documented behavior, including network access to the OpenAI API. This undermines transparency and informed consent for operators, making it easier to deploy a skill with broader access than expected.
