Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill invokes a Python script that uses both environment variables and network access, but the skill manifest does not declare those capabilities as permissions. This creates a transparency and governance gap: the agent may access sensitive credentials and perform external actions without explicit permission scoping or user-visible declaration, which is especially risky here because the action triggers irreversible public publication to a WeChat audience.
