Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill metadata does not explicitly declare permissions, yet the documented usage clearly relies on reading environment variables, local files, and making outbound network requests. This is dangerous because reviewers and users may underestimate the skill's operational reach, especially where secrets and external data transfer are involved.
