Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation describes capabilities to read environment variables, read and write local files, and make network requests, but it does not declare permissions accordingly. This weakens user and platform visibility into what the skill can access, increasing the chance that sensitive operations like API key handling, config writes, or remote requests occur without informed consent. In this context those capabilities are expected for a TTS skill, but the undeclared access is still a security transparency issue.
