Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill advertises API-driven behavior and explicitly relies on environment variables, local files, and network access, but it does not declare permissions for those capabilities. That creates a transparency and governance gap: a caller may invoke a skill with broader access than expected, including reading secrets from env and making outbound requests to an n8n instance. In this context, undeclared capabilities are more dangerous because the skill can activate, execute, and create workflows that may themselves trigger external side effects.
