Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill uses environment variables, local token files, shell commands, and network access, but does not declare corresponding permissions. This weakens user awareness and any permission-gating model, especially because the skill reads credentials/tokens from disk and sends authenticated requests to an external service.
