Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill instructs users to configure an API key and invokes an external Python script that likely uses environment variables and network access, but the skill does not declare these capabilities. Undeclared sensitive capabilities reduce transparency and can bypass user expectations or platform policy checks, especially because the script can exfiltrate secrets or make unintended remote requests.
