Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill clearly requires an environment variable and performs outbound network operations, but it does not declare explicit permissions for those capabilities. That weakens platform-level review and user awareness, making secret use and data egress easier to hide or misunderstand. In this context, the skill is expected to call a remote API, so the behavior is somewhat context-aligned, but the missing declaration still reduces transparency and increases operational risk.
