Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 81% confidence
- Finding
- The skill documentation declares no permissions even though the implementation uses environment variables and network access. This weakens reviewability and user consent because operators may not realize the skill can read secrets such as API keys and make outbound requests to third-party services. In a skill that also integrates Feishu and web endpoints, undocumented capabilities increase the chance of unsafe deployment assumptions.
