Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation explicitly describes executable entrypoints, build/run steps, and use of environment variables for model API keys, which indicates code can access network services and secrets despite no declared permissions. This creates a trust and transparency gap: a user or platform may assume the skill is low-privilege while it can actually make outbound requests and consume sensitive credentials.
