Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares runtime requirements and documents execution of a Python script that reads environment variables, performs network access, and writes query files, but it does not declare corresponding permissions in a first-class permission model. This creates a transparency and governance gap: the agent or reviewer may underestimate what the skill can access, especially the API token in NOAH_API_TOKEN and any locally written parameter files.
