Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation indicates use of both network access and an environment variable containing an API credential (`KMA_SERVICE_KEY`), but no explicit permissions are declared. This creates a real security gap because agents or reviewers may not have clear, enforceable visibility into the skill's required capabilities, and any script with network access plus secret access can exfiltrate the key or send unexpected outbound requests if the implementation is compromised.
