Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation clearly relies on environment-based secret handling (`NOTION_TOKEN`) and command execution, but no explicit permission declaration is present. This creates a transparency and policy gap: an agent or reviewer may underestimate that the skill consumes credentials and performs external API actions, increasing the chance of unsafe use or overbroad deployment.
