Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly requires sensitive capabilities at runtime: reading an API key from the environment, making outbound network requests to a third-party service, and writing a generated HTML file to disk. However, the manifest does not declare these operational permissions, which creates a transparency and policy-enforcement gap: hosts may under-evaluate the risk, fail to sandbox appropriately, or expose users to unexpected file/network behavior.
