Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to access environment variables and make outbound network requests, but no permissions are explicitly declared. That creates an authorization gap: a user invoking the skill may not realize it can read local secrets such as DATAIFY_API_TOKEN and transmit data to an external API endpoint. In this context, the behavior is central to the skill’s function, so it appears operational rather than malicious, but it still increases risk because secret access and exfiltration paths are not transparently constrained.
