Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to read a locally saved environment variable (`DATAIFY_API_TOKEN`) and make outbound network requests to a third-party API, but no declared permissions are present. That mismatch weakens the trust boundary: a user or platform reviewer may not realize the skill can access local secrets and transmit data externally. In this context, the behavior is expected for the skill’s function, but it still represents a real capability/permission transparency issue.
