Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation instructs use of environment variables for API credentials and multiple scripts that call an external service, but the skill does not declare corresponding env/network permissions. Undeclared sensitive capabilities reduce transparency and policy enforcement, increasing the chance that credentials or outbound access are used without proper review.
