Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill requires access to an environment secret and networked execution, but those capabilities are not explicitly declared as permissions in the skill metadata. That mismatch weakens review and containment because a consumer may not realize the skill can exfiltrate data or make external requests when invoked.
