Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation indicates use of environment variables and outbound network access (`curl` to a configured host), but no permissions are declared to reflect those capabilities. This creates a trust and review gap: operators may approve or run the skill without realizing it can read configuration secrets and communicate over the network to a non-local default IP.
