Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill uses sensitive capabilities—environment variables for credentials and outbound network access to the Appian API—but does not explicitly declare permissions. That creates a transparency and policy-enforcement gap: operators may approve or run the skill without realizing it can access secrets and communicate externally, increasing the risk of unintended credential use or data export.
