Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation indicates use of environment variables (`SIMMER_API_KEY`, `TAVILY_API_KEY`) and outbound network access to Simmer, Tavily, and third-party stats sources, but no corresponding permissions are declared. This creates a capability/permission mismatch that can mislead operators and prevent proper sandboxing or policy review, increasing the risk of secret exposure or unintended external requests when the linked script is run.
