Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill clearly relies on environment variables and outbound network access, yet it declares no permissions or equivalent capability metadata to warn users and hosting platforms. This creates a transparency and policy-enforcement gap: agents may invoke external requests and access configuration without an explicit trust signal, increasing the chance of unintended data disclosure or policy bypass.
