Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill clearly uses sensitive capabilities: it reads multiple credential-bearing environment variables, makes outbound network requests to Amazon SP-API, and writes files via report output options, yet the metadata declares only runtime requirements and no explicit permissions model. This creates a transparency and policy gap: an agent or platform may grant or execute the skill without users understanding that secrets will be consumed and data may be written or exfiltrated over the network.
