Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares required environment variables and clearly performs outbound network operations, yet no explicit permissions are declared. This weakens user consent and platform control because a user may install a seemingly simple search skill without being warned that it reads secrets and transmits data externally.
