Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill documentation declares no permissions, but the described helper usage and referenced functionality imply access to environment variables and network resources. Undeclared capabilities are dangerous because reviewers and deployers may trust the skill to be local-only while it can reach external services or read runtime configuration, which weakens informed consent and security review.
