Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill exposes sensitive capabilities via `allowed-tools: [bash]` plus documented use of environment variables, local file reads (`config.json`, image/content files), and networked API calls, yet it does not declare corresponding permissions in a structured way. This can mislead policy enforcement or reviewers about the skill's real access level, increasing the chance that secrets such as `HT_SKILL_TOKEN` or local file contents are accessed or transmitted without adequate scrutiny.
