Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill performs sensitive capabilities—reading a saved API token from the environment and sending user-supplied URLs and parameters to an external network endpoint—but does not declare permissions or surface this clearly as part of a permission model. That creates a transparency and governance gap: the agent may access local secrets and transmit data off-platform without an explicit capability declaration users or reviewers can evaluate.
