Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly requires environment-variable access for credentials and network access to Fastmail APIs, but SKILL.md does not declare permissions. This weakens transparency and policy enforcement because an agent or reviewer cannot easily verify that the skill will access secrets and send data over the network before use.
