Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes a Python script that uses network access to call the Feishu IM API and reads secrets from environment variables or a local config file, but the manifest does not declare corresponding permissions. This creates a transparency and governance gap: operators may enable the skill without understanding that it can access credentials and make outbound requests, which can lead to unintended data exposure or policy violations.
