Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documentation describes capabilities that rely on environment variables and outbound network access, but it does not declare permissions or provide explicit capability boundaries. In an agent ecosystem, this mismatch can cause operators to grant or inherit broader access than expected, reducing transparency and increasing the chance of unintended credential use or remote data access.
