Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to read a locally saved API token from the environment and submit network requests, but it declares no permissions or trust boundaries for those capabilities. Hidden or undeclared access to env and network increases the risk of unexpected secret use and outbound data transmission, especially in a skill that can be broadly activated.
