Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill requires environment secrets and clearly performs networked actions, but it does not declare corresponding permissions. This undermines the trust boundary for users and reviewers because the skill can access credentials and call external services without an explicit permission model, increasing the chance of unintended data exposure or unauthorized external actions.
