Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly depends on both environment access (`ZILLAPI_KEY`) and outbound network access to Zillapi, but it does not declare explicit permissions despite those capabilities being required. This creates a transparency and governance gap: operators may enable the skill without realizing it can read secrets from the environment and transmit user-supplied property queries to an external service.
