Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly performs sensitive actions including reading environment variables, writing files, and making network requests, yet it does not declare permissions. This creates a transparency and consent problem: a host or user may not realize the skill can access secrets like USA_API_KEY, fetch remote content, or write generated artifacts locally. The context increases concern because the skill explicitly handles API keys and can send them to a configurable base URL.
