Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to access environment variables for `DATAIFY_API_TOKEN` and make outbound network requests to an external API, but it does not declare corresponding permissions. That mismatch is a real security issue because it hides sensitive capabilities from the permission model and can lead to unauthorized token access or unexpected data exfiltration to a third-party service.
