Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill requires environment and network access to read an API key and send external requests, but it declares no corresponding permissions. This reduces transparency and can cause users or the host agent to authorize behavior they did not clearly consent to, especially because the skill transmits user queries and a configured credential to a third-party service.
