Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to read environment variables for a token, read local reference files and scripts, and make external network/API calls, yet no declared permissions are present. This creates a capability/consent mismatch: the platform or reviewer may underestimate what the skill can access and transmit, increasing the risk of accidental secret exposure or unauthorized outbound requests.
