Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs use of an API key via --api-key or GEMINI_API_KEY, which means it can access sensitive environment-backed secrets, but the metadata shown does not declare permissions or clearly bound that capability. Undeclared secret access increases the chance of accidental exposure, misuse, or execution in contexts where users did not realize credentials would be consumed.
