Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs use of a bundled CLI script to make external API calls and references environment-based configuration, yet the skill declares no permissions. This creates a transparency and policy-bypass risk because a caller may not realize the skill needs network and environment access before it attempts external disclosure or reads configuration such as VIBEVC_BASE_URL.
