Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documentation and metadata indicate use of an API key, local file input/output, and a third-party network call, but no explicit permissions are declared to match those capabilities. This creates a policy and review gap: a host may allow the skill to access sensitive environment variables, read workspace files, write outputs, and transmit data externally without users or enforcement layers having a clear permission declaration to validate against.
