Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill explicitly instructs the agent to access a locally saved environment token and make outbound network requests, but no declared permissions are present. This creates a capability/consent gap: a host system may expose secrets or allow external calls without users realizing the skill needs those powers, increasing the chance of unintended token use or data egress.
