Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill metadata declares required binaries and environment variables and the workflow clearly invokes Python scripts that will call an external API, but it does not declare corresponding permissions in a way that transparently informs the hosting agent/user about shell, network, and secret access. This creates a trust gap: a user may authorize or run the skill without understanding that their prompt content and API key will be used by executable code with outbound connectivity.
