Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documents use of environment variables, network access, local cache files, and persistent subscription storage, but the manifest does not declare these capabilities. Hidden or undeclared capabilities reduce transparency and prevent users or hosting systems from making informed trust decisions, especially because the skill performs file writes and external API calls. In this context the issue is more dangerous because the skill persists data locally and accesses secrets via environment variables.
