Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill clearly uses sensitive capabilities (environment secrets, file input, and outbound network access) but does not declare explicit permissions. That weakens platform-level review and user understanding, and can allow a skill with privileged behavior to run with less scrutiny than intended. In this context the risk is elevated because the skill handles an API private key and performs high-impact financial actions against an external invoicing service.
