Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill requires access to an environment variable (`VETO_API_KEY`) and sends approval requests over the network, but it does not declare these capabilities in its metadata. This creates a transparency and governance gap: agents or platforms may invoke the skill without realizing it can exfiltrate data to an external service or depend on sensitive secrets.
