Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 78% confidence
- Finding
- The skill documentation references use of environment-based secrets such as `RESEND_API_KEY` and operational scripts, but the skill metadata does not declare corresponding permissions or capability requirements. This can mislead users and hosting systems about what sensitive resources the skill needs, weakening reviewability and increasing the chance of unsafe secret handling or unexpected access during execution.
