Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly requires access to an environment secret (`CLOUDFLARE_API_TOKEN`) and performs outbound network/API operations, yet it declares no corresponding permissions. This creates a transparency and governance gap: an agent or reviewer may underestimate the skill's access to credentials and ability to make external state-changing requests.
