Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares no required tools or permissions, yet its documented workflow explicitly uses environment variables, network access to an external API, and file writes for report generation. This is dangerous because the platform or user may grant broader capabilities than expected without informed consent, undermining least-privilege controls and making hidden data access or persistence harder to audit.
