Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documents capabilities to read environment variables, write local configuration, and send network requests, yet it declares itself as a random-number service without corresponding permission transparency. This creates a trust gap: users and orchestrators may treat it as low-risk utility code while it can persist secrets and exfiltrate data to an external API.
