Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises and demonstrates use of sensitive capabilities including environment-secret access (`AIMLAPI_API_KEY`), network calls to an external API, and file read/write via script arguments and outputs, but it does not declare corresponding permissions. That mismatch weakens policy enforcement and review, making it easier for an agent to invoke external communication or handle local data in ways operators did not explicitly approve.
