Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill requires environment access for `DIDIT_API_KEY` and makes outbound network requests, but it does not declare corresponding permissions. Undeclared capabilities reduce transparency and can undermine platform security controls, making it harder for users or policy engines to assess what the skill can access.
