Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares capabilities that require environment-variable access and outbound network use, but it does not explicitly declare permissions for them. This creates a transparency and governance problem: users or hosting systems may not realize the skill can access secrets such as GEMINI_API_KEY and contact external services, which weakens review and consent controls. In this context, network and env access are expected for weather retrieval and image generation, so the issue appears to be incomplete permission declaration rather than overtly malicious behavior.
