Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill explicitly requires an API key from the environment and performs outbound network requests, but it does not declare corresponding permissions. This creates a capability/visibility gap: operators may invoke the skill without realizing it can transmit user prompts and possibly sensitive data to an external service.
