Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 80% confidence
- Finding
- The skill documents use of environment variables to access Metricool credentials, but the skill metadata does not declare permissions or clearly signal that it requires secret access. This can mislead users and automated policy systems about the skill's capabilities, increasing the chance that credentials are exposed to a skill that was not transparently permissioned.
