Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs use of an environment-sourced API key and outbound network access, but no corresponding permissions are declared. This creates a transparency and policy-enforcement gap: a host may permit the skill to run without clearly signaling that it can access secrets and call external services, increasing the risk of unintended credential use or data exfiltration through the documented API workflow.
