Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares no permissions, yet its instructions clearly require access to environment variables, file writing, and network APIs. This mismatch weakens user and platform oversight because the skill can read secrets, write artifacts to disk, and contact remote services without transparent capability disclosure. In this context, the risk is elevated by the requirement to persist responses locally and use API keys from the environment.
