Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation instructs use of an environment variable (`GEMINI_API_KEY`) and an explicit `--api-key` parameter, but the skill declares no permissions or capability metadata for environment access. That mismatch can cause secret-handling behavior to be hidden from the permission model and makes it easier for agents to access or request sensitive credentials without transparent review.
