Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation instructs users to supply an API key via an environment variable and to contact an external service, which means the skill uses env and network capabilities. If the skill does not explicitly declare those permissions, users and the host system lack clear notice that secrets and outbound requests are involved, weakening consent and review controls. In this context the behavior appears aligned with the tool's purpose, so this looks like an undeclared-capability issue rather than overtly malicious behavior.
