Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill declares no permissions, yet its documented behavior includes reading environment variables, writing to local files (.env), and making network requests. This is dangerous because it hides the true trust boundary from users and reviewers, making credential handling and external data flows less visible and harder to audit.
