Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill invokes scripts that require environment-variable access and outbound network access, but these capabilities are not explicitly declared as permissions. This weakens reviewability and user consent because a caller may not realize the skill can read secrets from a .env file and communicate with external services.
