Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill requires environment-stored Feishu credentials and instructs use of a network-capable upload script, but it does not declare those capabilities or permissions explicitly. This weakens transparency and reviewability, making it easier for a skill to access secrets and make outbound requests without users understanding the full trust boundary.
