Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation indicates access to sensitive environment data (`MENTIONSAPI_KEY`) and external network interaction, but it does not declare explicit permissions. This creates a transparency and policy-enforcement gap: a host may expose credentials or allow outbound requests without users and orchestrators having a clear, machine-readable permission model to review or restrict.
