Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares no permissions while its documented behavior clearly requires environment variable access and network communication. This is dangerous because it hides the true trust boundary from reviewers and users, making it easier to install a plugin that can exfiltrate data, open callback surfaces, or communicate with external services without explicit consent.
