Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill clearly uses sensitive capabilities: it reads an API token from the environment, performs outbound network requests to APIFY, and documents local cache reads/writes. If the skill framework expects explicit permission declarations, omitting them weakens reviewability and can cause users or agents to invoke a networked, stateful skill without understanding its access scope.
