Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly requires environment access for DASHSCOPE_API_KEY and network access to a remote SSE endpoint, but it does not declare an explicit permission or allowed-tools scope. This weakens least-privilege controls and makes it harder for users or hosting platforms to understand and constrain what the skill can access.
