Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation indicates use of environment variables and outbound network access, but it does not declare those permissions explicitly. Hidden or undeclared capabilities reduce transparency for reviewers and users, making it easier for a skill to access secrets such as API keys and send data off-platform without clear authorization boundaries.
