Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill invokes local Python scripts, reads reference files, accesses environment variables for API tokens, and performs network requests, but it declares no permissions or equivalent capability boundaries. This creates a trust and review gap: users and platforms may not realize the skill can access secrets and exfiltrate data over the network, increasing the risk of unintended token disclosure or unauthorized external calls.
