Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs use of environment secrets, local file access via `.env`, and outbound network access to the Civitai API, but the finding indicates these capabilities are not explicitly declared. Undeclared sensitive capabilities reduce transparency and can bypass permission-review expectations, which is risky because the skill also builds authenticated download URLs that may expose tokens if mishandled.
