Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill instructs use of an API key via --api-key or GEMINI_API_KEY and therefore relies on environment-secret access, yet no explicit permissions are declared. This creates an authorization and transparency gap: an agent may access sensitive environment data without the user clearly understanding that secret material is in scope.
