Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares no explicit permissions while clearly requiring environment secret access and outbound network access to a third-party API. This mismatch reduces transparency and can cause an agent or user to invoke a financially sensitive workflow without understanding that secrets and external calls are involved.
