Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill explicitly instructs users to export sensitive session credentials from browser storage and uses network access to call a third-party API, yet no permissions or trust boundaries are declared. This creates a real security issue because users are encouraged to grant powerful capabilities and provide secrets without transparent disclosure, making accidental credential misuse or overreach more likely.
