Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs use of environment variables for a Telegram bot token and chat ID and performs outbound network transmission, but it does not declare corresponding permissions. That creates a transparency and governance gap: users or enforcement systems may not realize the skill can access secrets and exfiltrate workspace files to an external service, which is especially sensitive because the stated purpose is uploading local markdown files off-platform.
