Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares only runtime requirements under metadata but does not explicitly disclose the sensitive capabilities it exercises: environment secret access, network access, and local file read/write. That under-specification matters because the skill can read THRD_API_KEY, call remote services, and persist local state such as cached OpenAPI data or cursor files, which expands the trust boundary beyond what a consumer may expect.
