Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill clearly documents use of the New Relic CLI against remote APIs, which implies network access, but the file does not declare permissions for that capability. Missing permission declarations weaken review and enforcement boundaries, making it easier for a skill with API-key-backed access to contact external services without explicit governance. In this context, the risk is elevated because the skill supports both read and write operations against observability and alerting resources.
