Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill metadata declares no permissions, yet the content describes capabilities consistent with reading environment variables, reading/writing files, and making network requests. In a gateway/key-management skill, these undeclared capabilities are security-relevant because they can expose API keys, persist sensitive usage data, and call external model providers without explicit user or platform visibility.
