Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation indicates use of environment variables and outbound network access, but no permissions are declared. This creates a transparency and governance gap: agents or reviewers may not realize the skill can read secrets such as OPENAI_API_KEY and transmit data externally, increasing the chance of unintended secret use or data exfiltration through normal operation or later script changes.
