Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares powerful capabilities in metadata and behavior—environment variable access, network access, and file output via `--output`—but does not declare explicit permissions. This is dangerous because the skill operates with an Admin API key and can transmit sensitive billing and API-key data to an external service while also writing potentially sensitive results to disk without a clear permission model.
