Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill metadata declares outbound network use and an environment variable requirement, but there is no explicit top-level permissions declaration aligned with those capabilities. This can mislead operators and automated policy systems about what the skill actually needs, reducing transparency and making risky capabilities easier to approve unintentionally.
