Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill declares only `allowed-tools: [exec]` while the documented behavior clearly depends on environment variables and outbound requests to Google Maps APIs. This creates a permissions/behavior transparency gap: operators may approve the skill without understanding that it reads API keys from the environment and transmits user-supplied locations over the network.
