Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation describes use of environment variables and networked OCR/multimodal services, but no explicit permission declaration is shown. That creates a transparency and policy-enforcement gap: operators may invoke a skill that can read runtime context and perform outbound requests without an explicit permission review. In this context, the risk is real because the skill can access session-related environment data and transmit document content to remote services.
