Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly requires environment-variable access and outbound network access, yet it declares no permissions. That mismatch can bypass user/operator expectations and weakens governance because a skill that can read secrets and send data externally is more dangerous when those capabilities are implicit rather than explicitly disclosed.
