Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to access environment variables for `DATAIFY_API_TOKEN` and make outbound network requests to a third-party API, but the skill declares no corresponding permissions. This creates a permission-transparency gap: a reviewer or platform policy engine may not realize the skill can read secrets and transmit data externally, increasing the risk of unintended secret use or unauthorized exfiltration.
