Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares required environment variables and clearly relies on outbound API calls, but it does not declare explicit permissions for env and network access. Missing permission declarations weaken review and enforcement boundaries, making it easier for a skill to access secrets or external endpoints without transparent authorization metadata.
