Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs users to set and rely on an environment variable for an external API key, but the skill metadata shown does not declare corresponding permissions or capability requirements. This creates a transparency and governance gap: the skill can access sensitive credentials and send user data to a third-party service without clearly declaring that behavior to the hosting platform or user.
