Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation indicates capabilities to read environment variables, access local files, and make network requests, but these capabilities are not explicitly declared as permissions. That creates a transparency and governance gap: users or hosting platforms may not realize the skill can read credentials from the environment or fallback config and transmit data to a remote service.
