Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares access to sensitive environment variables and clearly relies on networked behavior, but it does not declare explicit permissions for those capabilities. That weakens the trust boundary for users and tooling because the skill can handle API keys and communicate externally without a clear permission contract. In a skill that integrates payments, webhooks, Telegram, and an LLM API, hidden or implicit capabilities materially increase security and review risk.
