Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill requires access to an environment variable containing an API key and performs network-based lookups, but it does not explicitly declare permissions for those capabilities. Undeclared sensitive capabilities reduce transparency and can bypass review expectations, making it easier for a skill to exfiltrate secrets or make unintended external requests if the implementation changes or is compromised.
