Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares an environment variable requirement and describes file persistence, network calls, and state management, but does not declare corresponding permissions. This creates a transparency and policy-enforcement gap: a user or platform may approve the skill without understanding it can access credentials, write local state, and transmit data externally.
