Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation indicates use of environment variables for API credentials and network access to external services, but it does not declare corresponding permissions. Undeclared capabilities reduce transparency and can bypass user expectations or policy controls, especially for a skill that performs external requests and reads secrets from the environment. In this context, the shopping-search functionality makes network and env access expected, which lowers suspicion of malice but does not remove the security risk of silent capability use.
