Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares no explicit permissions even though it clearly requires environment-variable access and network access to external APIs. This mismatch can mislead users and host frameworks about the capability and trust boundary of the skill, reducing informed consent and weakening policy enforcement.
