Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes a Node.js script, consumes environment variables including an API key, and makes outbound network requests to a fixed third-party transcription service, yet no permissions are declared. This creates a mismatch between the skill's actual capabilities and its stated trust boundary, which can lead to over-privileged or non-transparent execution and exposure of sensitive data such as URLs, media metadata, and credentials.
