Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares use of environment variables and network access to contact an external API, but the file does not declare explicit permissions beyond tool requirements. This can weaken security review and user awareness because the skill is capable of transmitting user-scoped data and credentials off-platform without a clear permission model.
