Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill explicitly instructs users to store Etsy API credentials and run OAuth-related scripts, which implies access to environment secrets and outbound network use, yet no permissions are declared. This is dangerous because users and security controls cannot accurately assess or constrain the skill's capabilities, increasing the chance of overbroad secret exposure or unexpected API activity.
