Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documentation describes capabilities to read environment variables, read and write local files such as `.env` and `~/.youjia/key.json`, and perform network requests, but it does not declare any corresponding permissions. This creates a transparency and consent problem: a host agent or user may invoke the skill without understanding that it can persist secrets locally and access external services, increasing the risk of unintended secret exposure or unauthorized side effects.
