Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill requires access to the KEYAPI_TOKEN environment variable via metadata but does not declare explicit permissions in a way that transparently communicates its sensitive capability surface. This matters because the skill also instructs users to run Node-based commands against a remote MCP endpoint, so undisclosed env access can expose secrets to code paths the user may not expect.
