Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares environment-variable requirements and clearly instructs users to make authenticated network requests, yet the static finding indicates those capabilities are not properly declared as permissions. That creates a transparency and governance problem: the skill can access secrets and transmit data externally without clear permission scoping, increasing the chance of unreviewed secret use and unexpected outbound data flow.
