Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs the agent to run a Python analyzer that fetches data from npm, PyPI, and GitHub and may read a GITHUB_TOKEN from the environment, yet the skill declares no corresponding permissions. This creates a capability/permission mismatch that can cause unreviewed network access and exposure of environment-derived secrets in an execution context that appears more constrained than it really is.
