Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to read an API token from the environment and perform external network calls, but the skill metadata does not declare those capabilities or permissions. Undeclared access to secrets and outbound requests weakens reviewability and consent boundaries, increasing the risk of accidental secret use or data exfiltration through the invoked script.
