Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly relies on sensitive capabilities (`BRICKOWL_API_KEY` from the environment and outbound network access to the BrickOwl API) but does not declare permissions. That mismatch can bypass platform trust/consent expectations, making users or orchestration layers unaware that the skill can access credentials and transmit data externally.
