Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill requires access to sensitive environment variables (`WHOOP_CLIENT_ID`, `WHOOP_CLIENT_SECRET`, `WHOOP_REFRESH_TOKEN`) but does not declare corresponding permissions. This weakens user visibility and platform enforcement around secret access, making accidental overreach or unreviewed credential handling more likely.
