Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly requires access to environment variables, local file reads/writes for caching, and network access to Apify, but it does not explicitly declare permissions. This creates a transparency and consent problem: users may invoke the skill without realizing it can transmit data to a third party and persist data locally.
