Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill requires an API key via environment variables and performs outbound web crawling through a third-party service, but it does not declare permissions for env or network access. This weakens security transparency and policy enforcement, making it easier for an agent or operator to invoke external access and secret-dependent behavior without explicit review.
