Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill explicitly relies on environment variables for database connection details and on live MySQL connectivity, but no permissions are declared. That creates a capability transparency gap: a host or reviewer may not realize the skill can access sensitive credentials and exfiltrate database contents over the network. In a database-access skill, undeclared env and network access materially increase risk because the skill can reach production data stores directly.
