Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares environment-variable requirements and clearly initiates outbound network communication to a third-party service, but it does not declare permissions accordingly. This creates a transparency and consent problem: an agent runner or user may not realize the skill can read secrets and send data off-host, increasing the risk of unintended API key exposure or external data transmission.
