Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly relies on environment secrets, writes output files, and sends data over the network, but it does not declare permissions to make those capabilities explicit to users or the platform. This weakens transparency and consent, especially because audio content and API credentials are involved, and can lead to users invoking a skill without understanding its access scope.
