Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares an environment variable (`OPENAI_API_KEY`) and clearly performs networked transcription, but there is no explicit permissions declaration beyond envVars in the skill metadata. That mismatch weakens operator visibility into the skill's real capabilities and can lead to over-trusting a plugin that handles sensitive audio and credentials.
