Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill uses sensitive capabilities beyond what it explicitly declares: it requires an environment secret (`SKILLBOSS_API_KEY`) and performs network access to an external TTS service, but those capabilities are not formally declared as permissions. This creates a transparency and policy-enforcement gap, making it easier for the skill to access secrets or exfiltrate user-provided text without reviewers or runtime controls clearly understanding its privilege needs.
