Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill requires environment secrets and clearly performs outbound network operations, but it does not declare explicit permissions for those capabilities. That creates a transparency and governance gap: users or platforms may not realize the skill can access credentials and send data to external services, increasing the risk of unintended secret use or unreviewed data egress.
