Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill invokes local Python scripts, reads tokens from environment variables or CLI input, accesses bundled reference files, and makes authenticated network requests to a third-party API, yet no permissions are declared. This creates a transparency and governance gap: users or platform controls may not understand that the skill can access credentials and exfiltrate request data off-platform.
