Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly uses sensitive capabilities: reads credentials from environment variables and instructs the agent to perform networked API calls and production deployments, yet it declares no explicit permissions. That mismatch weakens policy enforcement and informed consent because a host may not surface to users that the skill can access secrets and make external changes.
