Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly depends on environment variables containing credentials and requires outbound network access to a Kimai instance, but no declared permissions are provided. That creates a governance and trust gap: an agent may be allowed to access secrets and external services without transparent permission scoping or user awareness.
