Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs use of environment variables, shell commands, and outbound network access to a third-party API, but it declares no permissions or trust boundaries. This creates a real security governance gap: an agent or reviewer may not understand that the skill can access secrets and make authenticated external requests, increasing the risk of unintended data disclosure or misuse of the API key.
