Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill documentation indicates use of both environment variables and outbound network access (`MIMO_API_KEY`, remote TTS API), but no permissions are declared. Undeclared capabilities undermine user/operator awareness and policy enforcement, increasing the risk of silent data egress or misuse of secrets even if the intended function is legitimate TTS synthesis.
