Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to read a locally saved API token from the environment and submit network requests, but no explicit permission declaration or trust boundary is documented. Hidden access to environment secrets plus outbound network use increases the risk of unintended secret exposure, unauthorized API use, and makes review harder because the capability is implicit rather than declared.
