Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill describes code that reads environment variables, performs network requests, and manages funds, yet it declares no permissions. That mismatch reduces user visibility into sensitive capabilities and can lead an agent or reviewer to approve a skill without understanding it can access secrets and transmit data externally.
